SYS::ONLINE
Wasteland.
Briefs1798
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-71985 2026-08-08

MSI Radix AXE6600 Router Hit by Critical Command Injection (CVE-2026-71985)

"An unauthenticated command injection flaw in the MSI Radix AXE6600's `accesscontrol` function lets remote attackers run arbitrary commands and gain root on affected routers, scoring CVSS 9.8."

An unauthenticated command injection flaw in the MSI Radix AXE6600's accesscontrol function lets remote attackers run arbitrary commands and gain root on affected routers, scoring CVSS 9.8.

What Is It

CVE-2026-71985 is an OS command injection vulnerability (CWE-78) in MSI Radix AXE6600 router firmware version v781521. The flaw resides in the accesscontrol function, which fails to properly neutralize attacker-supplied input before passing it to the underlying system. Per the NVD record, remote attackers can exploit the function to execute malicious commands and obtain root privileges on the device.

The CVE was assigned and disclosed by VulnCheck ([email protected]) and is currently in "Received" status in the NVD, meaning the record has been submitted but has not yet completed NVD analysis. Readers should treat the record's contents as provisional and check the NVD entry for updates.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and a CVSS 4.0 score of 9.3 (CRITICAL). That combination, network attack vector, low complexity, no privileges, no user interaction, means an attacker needs nothing but reachability to the affected interface.

Impact is high across confidentiality, integrity, and availability. Successful exploitation yields root on the router itself, placing the attacker at the network edge with full control over traffic for everything behind it.

CVE-2026-71985 does not appear in CISA's Known Exploited Vulnerabilities catalog as of this writing, so active exploitation is not confirmed at this time.

What's Vulnerable

The NVD record contains no CPE match entries, so automated detection by CPE matching will not flag affected devices.

Patch Status

No fixed version, vendor patch, or CISA-mandated remediation deadline has been published for CVE-2026-71985. The only vendor-side resource currently referenced is the MSI Radix AXE6600 support page. Administrators should check that page for firmware updates and, in the interim, restrict network access to the router's management interface.

Sources