Sceawere

Vulnerability Detail

CVE-2026-71985UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MSI Radix AXE6600 Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
MSI
Product
Radix AXE6600
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-09T00:16:47.360Z",
  "pubdate": "2026-08-09T00:16:47.360Z",
  "executiveSummary": "An unauthenticated remote command injection vulnerability exists within the accesscontrol function of the MSI Radix AXE6600 router firmware version v781521. This security flaw enables remote threat actors to bypass standard security boundaries and execute arbitrary system commands directly on the underlying operating system.\nSuccessful exploitation of this vulnerability results in full system compromise, granting the attacker root privileges over the affected networking hardware. The primary impact includes complete loss of device integrity, unauthorized interception or manipulation of network traffic, and potential pivoting into internal network segments connected to the compromised router.\nThe vulnerability resides in how user-supplied input is handled by the vulnerable function without adequate sanitization or validation before being passed to the underlying system shell. Threat actors can leverage this vector over the network to deliver malicious payloads, execute arbitrary code, and establish persistent unauthorized access.\nGiven the severity of potential root-level compromise and network-based attack vector, this vulnerability presents a critical risk to organizational and residential network infrastructure utilizing the affected MSI router hardware.",
  "technicalDetails": "The vulnerability is classified as a command injection flaw originating within the accesscontrol function of the MSI Radix AXE6600 firmware version v781521. The root cause stems from improper neutralization of special elements or shell metacharacters within input parameters processed by the application logic before execution via system-level interface calls.\nExploitation occurs when an attacker transmits a maliciously crafted HTTP request or network packet containing arbitrary command payloads directed at the vulnerable accesscontrol component. Because the application fails to perform rigorous input validation or contextual output encoding, the injected command parameters are interpreted directly by the underlying shell.\nThe attack flow proceeds as follows: First, the remote adversary identifies the network exposure of the management interface or vulnerable endpoint hosting the accesscontrol function. Second, the attacker crafts a specialized payload embedding system commands designed for execution. Third, the payload is submitted to the target device via the vulnerable input vector.\nUpon receiving the request, the application passes the unsanitized input to the operating system shell execution routine. The shell parses and executes the embedded malicious commands with the highest privilege level available to the application context.\nPost-exploitation impact includes the immediate acquisition of root privileges on the underlying operating system. This grants the adversary complete administrative control over the device configuration, ability to disable security controls, deploy persistent backdoors, inspect network traffic passing through the router, and launch further attacks against internal network hosts."
}
CVE-2026-71985: MSI Radix AXE6600 Command Injection (CRITICAL Severity, CVSS: 9.8) - Sceawere