A command injection flaw in the alg function of MSI Radix AXE6600 router firmware v781521 lets unauthenticated remote attackers run arbitrary commands and gain root on the device.
What Is It
CVE-2026-71987 is an OS command injection vulnerability (CWE-78) in the MSI Radix AXE6600 Wi-Fi 6E tri-band gaming router. According to the NVD record, firmware version v781521 fails to properly handle input reaching the alg function, allowing remote attackers to inject and execute arbitrary commands on the affected device. Successful exploitation yields root privileges on the underlying system.
The vulnerability was disclosed by VulnCheck ([email protected]). Its NVD vulnerability status is currently Received, meaning the record was recently ingested and is still awaiting full analysis.
Why It Matters
The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. A CVSS 4.0 secondary score of 9.3 (CRITICAL) is also assigned. Every exploitability condition favors the attacker: network-reachable, low attack complexity, no privileges required, and no user interaction. Confidentiality, integrity, and availability impacts are all rated High.
Root-level command execution on a border router means full control of the device; traffic interception, persistence, and pivoting into the network behind it. There is no supplied CISA KEV entry for this CVE, so active exploitation has not been confirmed by KEV at this time, and no KEV-mandated remediation deadline or required action applies. The CVSS 4.0 exploit maturity field is Not Defined.
What's Vulnerable
- Vendor: MSI
- Product: Radix AXE6600 (Wi-Fi 6E Tri-Band Gaming Router)
- Affected versions: firmware from 0 up to and including v781521 (vendor-declared default status: affected)
No CPE entries are listed in the NVD record yet.
Patch Status
The supplied source material does not identify a fixed firmware version or a vendor advisory confirming a patch. The only vendor-side references are the MSI Radix AXE6600 product support page and the MSI homepage. Administrators should check the MSI support page for firmware updates and, in the interim, restrict remote administrative access to the device.
Sources
- NVD, CVE-2026-71987 (status: Received)
- VulnCheck Advisory; MSI Radix AXE6600 v781521 Command Injection via alg Function: https://www.vulncheck.com/advisories/msi-radix-axe6600-v781521-command-injection-via-alg-function
- MSI, Radix AXE6600 Wi-Fi 6E Tri-Band Gaming Router Support: https://us.msi.com/Networking/RadiX-AXE6600-WiFi-6E-Tri-Band-Gaming-Router/support
- MSI, Vendor Homepage: https://www.msi.com/