Sceawere
Vulnerability Detail
CVE-2026-71984UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MSI Radix AXE6600 Command Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- MSI
- Product
- Radix AXE6600
- Attack Type
- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-09T00:16:47.207Z",
"pubdate": "2026-08-09T00:16:47.207Z",
"executiveSummary": "The MSI Radix AXE6600 router running firmware version v781521 is susceptible to a critical command injection vulnerability localized within the urlfilter function.\nThis security flaw enables remote attackers to inject and execute arbitrary system commands directly on the underlying operating system.\nSuccessful exploitation of this vulnerability grants the adversary complete administrative control, resulting in the acquisition of root privileges on the affected device.\nThe presence of a remote command injection vulnerability in a core networking device introduces severe risk implications, including total compromise of network confidentiality, integrity, and availability.\nThreat actors possessing network access to the vulnerable endpoint can leverage this flaw to execute arbitrary payloads, manipulate device configurations, pivot into internal networks, and establish persistent unauthorized access.\nThe attack vector exploits inadequate input sanitization and improper neutralization of special elements within the urlfilter functionality, allowing shell metacharacters to be parsed and executed by the underlying system shell.",
"technicalDetails": "The vulnerability resides in the urlfilter function of the MSI Radix AXE6600 router running firmware version v781521, which fails to adequately sanitize user-supplied input prior to passing it to the underlying system execution environment.\nRoot cause analysis indicates an insecure implementation of command construction or API handling where parameters intended for URL filtering are concatenated directly into system shell commands without sufficient validation or escaping.\nThe attack flow begins when a remote attacker crafts a malicious HTTP request or interface interaction targeting the urlfilter component.\nBy appending shell metacharacters (such as semicolons, pipes, or backticks) combined with arbitrary system commands to the target parameter, the attacker forces the system shell to interpret the injected string alongside the intended administrative process.\nBecause the web application daemon or underlying service typically operates with elevated privileges, the execution of the injected payload inherits these permissions.\nConsequently, the arbitrary commands executed by the attacker run with full root privileges on the underlying Linux-based operating system.\nNetwork exposure encompasses remote access vectors capable of reaching the vulnerable administrative or routing interfaces that process urlfilter configurations.\nDepending on the configuration, this may be exposed via the local area network or potentially the wide area network if remote management interfaces are enabled.\nPost-exploitation impact is catastrophic, as obtaining root privileges allows the threat actor to disable security controls, install backdoors, intercept network traffic passing through the MSI Radix AXE6600, or utilize the compromised device as a staging point for lateral movement across the connected network infrastructure."
}