SYS::ONLINE
Wasteland.
Briefs1798
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-71987 2026-08-08

CVE-2026-71987: Critical Command Injection in MSI Radix AXE6600 Routers

"A command injection flaw in the `alg` function of MSI Radix AXE6600 router firmware v781521 lets unauthenticated remote attackers run arbitrary commands and gain root on the device."

A command injection flaw in the alg function of MSI Radix AXE6600 router firmware v781521 lets unauthenticated remote attackers run arbitrary commands and gain root on the device.

What Is It

CVE-2026-71987 is an OS command injection vulnerability (CWE-78) in the MSI Radix AXE6600 Wi-Fi 6E tri-band gaming router. According to the NVD record, firmware version v781521 fails to properly handle input reaching the alg function, allowing remote attackers to inject and execute arbitrary commands on the affected device. Successful exploitation yields root privileges on the underlying system.

The vulnerability was disclosed by VulnCheck ([email protected]). Its NVD vulnerability status is currently Received, meaning the record was recently ingested and is still awaiting full analysis.

Why It Matters

The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. A CVSS 4.0 secondary score of 9.3 (CRITICAL) is also assigned. Every exploitability condition favors the attacker: network-reachable, low attack complexity, no privileges required, and no user interaction. Confidentiality, integrity, and availability impacts are all rated High.

Root-level command execution on a border router means full control of the device; traffic interception, persistence, and pivoting into the network behind it. There is no supplied CISA KEV entry for this CVE, so active exploitation has not been confirmed by KEV at this time, and no KEV-mandated remediation deadline or required action applies. The CVSS 4.0 exploit maturity field is Not Defined.

What's Vulnerable

No CPE entries are listed in the NVD record yet.

Patch Status

The supplied source material does not identify a fixed firmware version or a vendor advisory confirming a patch. The only vendor-side references are the MSI Radix AXE6600 product support page and the MSI homepage. Administrators should check the MSI support page for firmware updates and, in the interim, restrict remote administrative access to the device.

Sources