SYS::ONLINE
Wasteland.
Briefs1798
Issues22
SinceFeb 2026
LIVE
CVE · Critical CVE-2026-71989 2026-08-08

MSI Radix AXE6600 Router Hit With Critical Root-Level Command Injection (CVE-2026-71989)

"A critical command injection flaw in MSI Radix AXE6600 router firmware v781521 is reported to allow unauthenticated remote attackers to run arbitrary commands and gain root on the device."

A critical command injection flaw in MSI Radix AXE6600 router firmware v781521 is reported to allow unauthenticated remote attackers to run arbitrary commands and gain root on the device.

What Is It

CVE-2026-71989 is an OS command injection vulnerability (CWE-78) in the porTrigger function of the MSI Radix AXE6600 gaming router. According to the advisory, remote attackers can exploit the issue through the alg function to execute malicious commands on the affected device and obtain root privileges on the underlying system.

The bug carries a CVSS v3.1 base score of 9.8 (Critical): vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, alongside a CVSS v4.0 score of 9.3 (Critical). Both scoring systems agree on the shape of the problem: network-reachable, low attack complexity, no privileges required, no user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

Root code execution on a border device amounts to a full compromise of the network perimeter. An attacker who lands porTrigger would be positioned to control DNS, traffic inspection, and lateral pivot into everything behind the router. As scored, the vulnerability requires no preconditions, no credentials, no clicks, which is the profile typically associated with opportunistic mass scanning.

No exploitation in the wild is confirmed in the supplied data, and CVSS v4.0 exploit maturity is listed as Not Defined.

What's Vulnerable

No CPE entries have been published for this record yet.

Patch Status

The NVD record is in Received status and lists no fixed version and no vendor patch advisory. Until MSI ships fixed firmware, operators should check the MSI support page for the Radix AXE6600 and restrict remote/WAN-side access to the router's management interfaces.

Sources