A critical unauthenticated command injection flaw in the MSI Radix AXE6600 router's wps.cgi interface lets remote attackers run arbitrary commands as root.
What Is It
CVE-2026-71983 is an OS command injection vulnerability (CWE-78) in MSI Radix AXE6600 router firmware version v781521. The wps.cgi interface fails to sanitize the pin2g, pin5g, and pin6g parameters. A remote attacker can inject malicious input through any of these parameters to execute arbitrary commands on the affected device and obtain root privileges.
The flaw was disclosed by VulnCheck ([email protected]).
Why It Matters
Every exploitability condition favors the attacker. The vulnerable interface is reachable over the network, requires no authentication and no user interaction, and needs no special conditions to trigger; an attacker only has to reach the router's web interface and send a crafted request.
Successful exploitation yields root on the device. On a network edge device, that means full control of the router that sits between the internal network and the internet: traffic interception and redirection, DNS manipulation, persistent implants surviving in firmware, and a pivot into everything behind it.
This CVE is not listed in CISA's Known Exploited Vulnerabilities catalog as of publication, so no KEV-mandated remediation deadline applies. Absence from KEV reflects what CISA has cataloged, not a determination that exploitation is not occurring in the wild.
What's Vulnerable
- Vendor: MSI
- Product: Radix AXE6600 (WiFi 6E Tri-Band Gaming Router)
- Affected versions: firmware v781521, the only version identified in the advisory. Earlier firmware releases have not been confirmed either affected or unaffected, and should be treated as potentially vulnerable until the vendor states otherwise.
- Attack surface: the
wps.cgiinterface, via thepin2g,pin5g, orpin6gparameters
Patch Status
The supplied source material does not identify a fixed firmware version or vendor patch. The advisory references MSI's official product support page for the Radix AXE6600, which is the authoritative location to check for updated firmware. Until a fix is confirmed, restrict network access to the router's web management interface, particularly from untrusted networks and the WAN side.
Sources
- VulnCheck Advisory; https://www.vulncheck.com/advisories/msi-radix-axe6600-v781521-command-injection-via-wps-cgi
- MSI Radix AXE6600 Support Page; https://us.msi.com/Networking/RadiX-AXE6600-WiFi-6E-Tri-Band-Gaming-Router/support
- MSI, https://www.msi.com/