Junglewise Threat Intelligence

CVE-2026-53876: MSI RadiX AX6600 OS command injection in web console

CVE-2026-53876 · Severity: high · CVSS 7.2 · Published 2026-06-17

Vendors: MSI.

Executive brief

The MSI RadiX AX6600 gaming router contains a security flaw that allows an authenticated administrator to execute unauthorized system commands. If exploited, an attacker with administrative access to the web management console could take full control of the device with root privileges. This could lead to complete service disruption, interception of network traffic, or the use of the router as a foothold for further attacks on the local network.

Technical details

An OS command injection vulnerability (CWE-78) exists in the web management console of the MSI RadiX AX6600 router. The flaw is located in the handling of administrative inputs, where the application fails to properly neutralize special elements used in OS commands. An attacker with network access and valid administrator credentials can exploit this to execute arbitrary commands with root-level privileges. The vulnerability is addressed in firmware version v781521 and later.

Affected products

  • Micro-Star International Co., Ltd. (MSI) RadiX AX6600 WiFi 6 Tri-Band Gaming Router firmware versions prior to v781521

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory
  • 2026-06-17: patched: Fixed in firmware version v781521

References