Executive brief
The MSI Radix AXE6600 is a WiFi 6E gaming router used to provide wireless network connectivity. A command injection vulnerability in its firmware allows remote attackers to execute arbitrary commands with root privileges, potentially giving attackers complete control over the device and any network it serves.
Technical details
A command injection vulnerability exists in the urlfilter function within MSI Radix AXE6600 firmware version v781521. The vulnerability allows remote, unauthenticated attackers to inject and execute arbitrary shell commands on the affected device by exploiting improper input sanitization in the URL filtering mechanism. An attacker can leverage this to obtain root-level access to the router's operating system. No authentication or user interaction is required to exploit this vulnerability. Patch availability and remediation timeline have not been disclosed.
Affected products
- MSI Radix AXE6600 v781521
Timeline
- 2026-08-09: disclosed