Sceawere

Vulnerability Detail

CVE-2026-71987UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MSI Radix AXE6600 Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
MSI
Product
Radix AXE6600
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-09T00:16:47.637Z",
  "pubdate": "2026-08-09T00:16:47.637Z",
  "executiveSummary": "An arbitrary command injection vulnerability exists within the alg function of the MSI Radix AXE6600 router running firmware version v781521. This security flaw enables remote attackers to execute arbitrary system commands directly on the underlying operating system of the affected hardware.\nSuccessful exploitation of this vulnerability leads to a complete compromise of the device confidentiality, integrity, and availability, allowing malicious actors to acquire root-level privileges. The primary impact involves unauthorized remote administrative control over the targeted networking equipment, facilitating potential lateral movement, traffic interception, or secondary payload deployment within the local network.\nThe vulnerability resides specifically in the router firmware processing logic associated with the alg function. Exploitation requires the attacker to interact with the vulnerable function, leveraging improper input sanitization or validation mechanisms within the firmware codebase to inject shell metacharacters or executable command sequences.\nGiven the nature of network edge devices, such vulnerabilities represent critical operational risks, exposing residential or enterprise perimeters to remote adversarial manipulation without necessarily requiring prior authentication depending on network exposure boundaries.",
  "technicalDetails": "The vulnerability is classified as a command injection flaw affecting the alg function within the firmware version v781521 of the MSI Radix AXE6600 router. The root cause stems from insufficient input sanitization and improper validation of parameters passed to the underlying operating system shell through the vulnerable alg component.\nDuring normal operations, the firmware likely constructs system command strings dynamically using user-supplied parameters intended for the alg function. Because the input parameters lack adequate filtering or escaping mechanisms for shell metacharacters, an attacker can supply specially crafted payloads that break out of the intended argument context and append arbitrary system commands.\nThe attack flow proceeds as follows: First, the remote attacker identifies network reachability to the vulnerable MSI Radix AXE6600 routing device. Second, the attacker formulates a malicious payload directed at the alg function interface, incorporating operating system command separators or execution operators. Third, upon receipt, the vulnerable firmware processes the input string and passes the concatenated command to the underlying system shell for execution.\nExecution of the injected payload occurs within the context of the privileged root user, granting the attacker complete administrative control over the underlying Linux-based operating system. Post-exploitation impact includes the ability to modify system configurations, extract sensitive data such as cryptographic keys or credentials, disable logging mechanisms, or install persistent backdoors to maintain long-term access.\nWhile specific authentication requirements and network exposure vectors depend on the device configuration, remote exploitation typically targets exposed management interfaces or exposed service handlers interacting with the alg function. The lack of robust parameterization and secure API design within the firmware component enables this severe security degradation."
}
CVE-2026-71987: MSI Radix AXE6600 Command Injection (CRITICAL Severity, CVSS: 9.8) - Sceawere