Junglewise Threat Intelligence

CVE-2026-71983: MSI Radix AXE6600 command injection in wps.cgi

CVE-2026-71983 · Severity: critical · CVSS 9.8 · Published 2026-08-08

Technologies: MSI Radix AXE6600. Vendors: MSI.

Executive brief

The MSI Radix AXE6600 router's WPS (Wi-Fi Protected Setup) configuration interface contains a command injection flaw that allows remote attackers to execute arbitrary commands with root privileges. An attacker can exploit unsanitized input parameters to take complete control of the router, potentially intercepting network traffic, modifying settings, or using the device as a pivot point to attack other systems on the network.

Technical details

The vulnerability is a command injection flaw in the wps.cgi interface affecting MSI Radix AXE6600 firmware version v781521. The pin2g, pin5g, and pin6g parameters are not properly sanitized, allowing attackers to inject arbitrary shell commands. The vulnerability is remotely exploitable without authentication, and successful exploitation grants root-level access to the router's operating system. Patched firmware versions should be applied to affected devices; administrators should check MSI's security advisories for available updates.

Affected products

  • MSI Radix AXE6600 v781521

Timeline

  • 2026-08-08: disclosed

References

Related threats