MSI Radix AXE6600 Router DMZ Function Command Injection
First seen Aug 10, 2026 · Updated Aug 10, 2026 · CVSS 9.8
A critical unauthenticated command injection vulnerability (CVE-2026-71986) exists in the dmz function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands and gain root access. With a CVSS score of 9.8, this flaw poses severe risk to any network relying on the affected device for perimeter security or connectivity.
Technical Analysis
CVE-2026-71986 is a command injection vulnerability in the dmz function of MSI Radix AXE6600 router firmware v781521, likely stemming from insufficient sanitization of user-supplied input passed to a system shell call within the router's web management interface. Successful exploitation grants remote attackers arbitrary command execution with root privileges, enabling full device takeover, traffic interception, DNS hijacking, and pivoting into internal networks. The CVSS 9.8 score reflects network-based attack vector, low complexity, and no authentication requirement, making mass exploitation via internet scanning highly feasible. Organizations using this router as a network edge device for offices or branch locations running AI agent infrastructure, RAG pipelines, or LLM tool-use servers behind it face risk of man-in-the-middle attacks, credential interception, and lateral movement into agent hosts, potentially exposing API keys, model endpoints, and sensitive data in transit.
Affected Systems
MSI Radix AXE6600 router, firmware version v781521, specifically the DMZ configuration function accessible via the router's management interface
Indicators of Compromise
- No specific IOCs published; monitor for anomalous outbound connections from router management interfaces and unexpected DMZ configuration changes
Remediation Steps
- 1
Apply Firmware Update
Check MSI's official support site for a patched firmware version addressing CVE-2026-71986 and apply immediately.
- 2
Restrict Management Access
Disable remote/WAN access to the router's administration interface and restrict management to trusted LAN IPs only.
- 3
Network Segmentation
Isolate the router from critical infrastructure, including any hosts running AI agent frameworks, LLM services, or RAG pipelines, using additional firewall layers.
- 4
Disable DMZ Feature
If not required, disable the DMZ function entirely until a patch is confirmed available.
- 5
Monitor for Exploitation
Review router logs for unusual command execution patterns, unexpected configuration changes, or unauthorized root-level access attempts.
- 6
Rotate Exposed Credentials
If the router was reachable from the internet, rotate any credentials, API keys, or secrets that traverse the network, especially those used by downstream AI agent systems.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.