A command injection flaw in the MSI Radix AXE6600 gaming router's portFw function lets unauthenticated remote attackers run arbitrary commands as root on affected firmware.
What Is It
CVE-2026-71988 is an OS command injection vulnerability (CWE-78) in MSI Radix AXE6600 router firmware version v781521. The flaw sits in the portFw function, which fails to properly neutralize attacker-supplied input before passing it to the underlying operating system. According to the disclosure, attackers can reach the vulnerable code path through the alg function to execute malicious commands and obtain root privileges on the device.
The bug carries a base score of 9.8 (CRITICAL) with metrics indicating a network-reachable attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and HIGH impact to confidentiality, integrity, and availability. Note that the published vector string is inconsistent with its own version label: it reads CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, pairing a CVSS 4.0 prefix with CVSS 3.1-style metrics (a 9.8 score and an S:U scope metric are both 3.1 constructs, not 4.0). The metric values themselves are internally coherent; the version label attached to them is not, and should be treated as unreliable pending NVD analysis. Separately, the reporting source, VulnCheck, assigned a CVSS 4.0 secondary score of 9.3 (CRITICAL).
Why It Matters
Full compromise with no authentication is the worst case for edge networking gear. The CVSS breakdown rates confidentiality, integrity, and availability impact all as HIGH, meaning a successful attacker gains complete control of the device. Root access on a router puts the attacker in the path of all traffic behind it: they can pivot into the internal network, alter DNS settings, capture credentials, or enroll the device into a botnet. Consumer and gaming routers are frequently internet-facing and rarely monitored, which widens the exposure window considerably.
There is no CISA KEV entry for this CVE in the supplied data, so active exploitation has not been confirmed by KEV at this time.
What's Vulnerable
- Vendor: MSI
- Product: Radix AXE6600 (WiFi 6E Tri-Band Gaming Router)
- Affected versions: firmware v781521 is the only version the advisory identifies as affected. Whether earlier firmware releases are also vulnerable is not established by the available source material; treat other versions as unassessed rather than confirmed safe.
Patch Status
The supplied source material does not identify a fixed firmware version or specify a required remediation action. MSI's official support page for the Radix AXE6600 is listed among the advisory references and is the appropriate place to check for firmware updates. The CVE record is in "Received" status at NVD, so analysis may still be pending.
Sources
- NVD, CVE-2026-71988: https://nvd.nist.gov/vuln/detail/CVE-2026-71988
- VulnCheck Advisory; MSI Radix AXE6600 v781521 Command Injection via portFw Function: https://www.vulncheck.com/advisories/msi-radix-axe6600-v781521-command-injection-via-portfw-function
- MSI Radix AXE6600 Support Page: https://us.msi.com/Networking/RadiX-AXE6600-WiFi-6E-Tri-Band-Gaming-Router/support
- MSI: https://www.msi.com/