criticalOther

MSI Radix AXE6600 Router Command Injection (CVE-2026-71987)

First seen Aug 10, 2026 · Updated Aug 10, 2026 · CVSS 9.8

routercommand-injectionrcefirmwareiotunauthenticatednetwork-infrastructure

A critical command injection vulnerability exists in the alg function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. With a CVSS score of 9.8, this flaw could enable full device takeover, network pivoting, and traffic interception on affected routers.

Technical Analysis

The vulnerability resides in the alg function of the firmware, which fails to properly sanitize user-supplied input before passing it to system-level command execution routines, enabling classic OS command injection. Successful exploitation grants remote, likely unauthenticated, attackers root-level access to the router's underlying Linux-based operating system. This level of access allows attackers to modify DNS/routing configurations, intercept or redirect traffic, deploy persistent malware or botnet implants (e.g., Mirai-style), and use the device as a pivot point into internal networks. Organizations running AI agent infrastructure, RAG pipelines, or LLM tool-use systems behind or near an affected router are at risk of traffic interception, DNS hijacking, or man-in-the-middle attacks that could expose API keys, credentials, or manipulate agent-to-tool communications in transit.

Affected Systems

MSI Radix AXE6600 router, firmware version v781521

Indicators of Compromise

  • No specific IoCs (hashes, IPs, domains) published at time of disclosure; monitor for anomalous outbound connections and unauthorized configuration changes on affected devices

Remediation Steps

  1. 1

    Apply Firmware Update

    Check MSI's official support site for a patched firmware release addressing the alg function command injection and apply it immediately.

  2. 2

    Restrict Remote Management

    Disable remote administration/WAN-facing management interfaces on the router until a patch is confirmed installed.

  3. 3

    Network Segmentation

    Isolate router administrative interfaces from general network traffic and restrict access to trusted management VLANs only.

  4. 4

    Monitor for Compromise Indicators

    Review router logs and DNS/routing configurations for unauthorized changes; reset to factory defaults and reconfigure if compromise is suspected.

  5. 5

    Firewall Rule Enforcement

    Block inbound traffic to router management ports from untrusted external sources.

CVE / Advisory IDs

CVE-2026-71987

Industries Most Exposed

consumer electronicssmall business networkingtelecommunicationscritical infrastructure (SOHO)technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.