Sceawere

Vulnerability Detail

CVE-2026-71989UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MSI Radix AXE6600 Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
MSI
Product
Radix AXE6600
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-09T00:16:47.953Z",
  "pubdate": "2026-08-09T00:16:47.953Z",
  "executiveSummary": "An unauthenticated remote command injection vulnerability has been identified in the MSI Radix AXE6600 router running firmware version v781521. The vulnerability resides within the port-triggering subsystem, specifically inside the porTrigger function. Remote attackers possessing network access to the device can leverage this flaw to execute arbitrary system commands with elevated privileges. Successful exploitation allows an adversary to achieve full administrative control, yielding root privileges on the underlying operating system.\nThe core risk implications involve total compromise of the affected routing hardware, potentially exposing internal networks to further pivoting, man-in-the-middle attacks, and unauthorized monitoring or manipulation of network traffic. The attack mechanism requires chaining or interaction through the alg function to improperly sanitize user-supplied input before it is passed to the underlying operating system shell. Given the severity of remote code execution coupled with root-level privileges, this vulnerability poses a critical threat to enterprise and home network security postures.",
  "technicalDetails": "The vulnerability is classified as a command injection flaw occurring within the porTrigger function of the MSI Radix AXE6600 firmware version v781521. The root cause stems from the insecure handling and processing of parameters supplied via the alg function, where input data is insufficiently validated, filtered, or escaped prior to being concatenated into system command execution routines.\nThe attack flow proceeds as follows: an attacker with network access crafts a malicious input payload designed to break out of the intended argument context and inject arbitrary shell commands. This payload is submitted to the vulnerable endpoint invoking the alg function, which subsequently triggers the flawed porTrigger logic. Because the application fails to sanitize the incoming parameters, the injected shell metacharacters and commands are directly interpreted and executed by the underlying system shell.\nThe vulnerable component is the firmware module responsible for port triggering configurations. Exploitation requires network connectivity to the management interface or accessible services exposed by the device, although specific pre-authentication or post-authentication constraints depend on the exact exposure of the alg functionality. The post-exploitation impact is catastrophic, as the injected commands inherit the privileges of the execution context, resulting in complete system compromise and the attainment of root privileges. This grants the attacker unbounded capability to read sensitive configurations, modify device behavior, install persistent backdoors, or disrupt network operations."
}
CVE-2026-71989: MSI Radix AXE6600 Command Injection (CRITICAL Severity, CVSS: 9.8) - Sceawere