Executive brief
The MSI Radix AXE6600 router's WPS (Wi-Fi Protected Setup) configuration interface contains a command injection flaw that allows remote attackers to execute arbitrary commands with root privileges. An attacker can exploit unsanitized input parameters to take complete control of the router, potentially intercepting network traffic, modifying settings, or using the device as a pivot point to attack other systems on the network.
Technical details
The vulnerability is a command injection flaw in the wps.cgi interface affecting MSI Radix AXE6600 firmware version v781521. The pin2g, pin5g, and pin6g parameters are not properly sanitized, allowing attackers to inject arbitrary shell commands. The vulnerability is remotely exploitable without authentication, and successful exploitation grants root-level access to the router's operating system. Patched firmware versions should be applied to affected devices; administrators should check MSI's security advisories for available updates.
Affected products
- MSI Radix AXE6600 v781521
Timeline
- 2026-08-08: disclosed