Sceawere

Vulnerability Detail

CVE-2026-71988UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MSI Radix AXE6600 Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
MSI
Product
Radix AXE6600
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-09T00:16:47.780Z",
  "pubdate": "2026-08-09T00:16:47.780Z",
  "executiveSummary": "The MSI Radix AXE6600 router firmware version v781521 suffers from a critical command injection vulnerability. This vulnerability resides within the portFw function and can be triggered via the alg function. The flaw allows remote attackers to execute arbitrary system commands with root privileges, leading to complete compromise of the affected routing device. The high severity of this issue stems from the combination of unauthenticated or remote attack vectors and the highest possible execution privilege level on the underlying operating system. Attackers capable of interacting with the vulnerable network services can leverage this flaw to achieve persistent control, intercept network traffic, pivot into internal network segments, or disable security controls. Remediation requires applying official vendor firmware updates or restricting administrative management interfaces from untrusted networks until a patch is deployed.",
  "technicalDetails": "The vulnerability is a classic command injection flaw originating from improper neutralization of user-supplied input passed to underlying system shell interpreters. Specifically, the vulnerable component is the portFw function, which fails to adequately sanitize parameters processed during the execution of the alg function. Attackers can craft malicious input payloads containing shell metacharacters or command separators and transmit them to the device via the exposed application interface. When the router processes the crafted request, the insecure function concatenates or passes the unsanitized input directly to a system shell command execution sink.\nThe attack flow proceeds as follows: First, the remote attacker identifies the network exposure of the vulnerable interface managing port forwarding or ALG configurations. Second, the attacker formulates a malicious payload designed to execute arbitrary system binaries or shell commands. Third, the attacker transmits this payload to the alg function, which subsequently hands the unsanitized data to the vulnerable portFw function. Fourth, the operating system executes the injected commands within the execution context of the root user, bypassing all standard security boundaries.\nBecause execution occurs with root privileges, the post-exploitation impact is total system takeover. An attacker can manipulate routing tables, inject malicious DNS configurations, install persistent backdoors, extract sensitive credentials, or utilize the compromised router as a staging point for internal network reconnaissance and lateral movement. Network exposure includes remote attack vectors, and exploitation does not require complex prerequisites other than reaching the vulnerable application interface."
}
CVE-2026-71988: MSI Radix AXE6600 Command Injection (CRITICAL Severity, CVSS: 9.8) - Sceawere