Executive brief
The MSI RadiX AXE6600 is a WiFi 6E gaming router used to provide wireless connectivity in homes and small businesses. A command injection vulnerability in the router's access control firmware allows remote attackers to execute arbitrary commands with root privileges, potentially giving an attacker complete control over the device and any data passing through it.
Technical details
The vulnerability is a command injection flaw in the accesscontrol function of the MSI RadiX AXE6600 router firmware (version v781521). An attacker can exploit this vulnerability remotely to execute arbitrary shell commands on the device, obtaining root-level access to the underlying system. The vulnerability allows unauthenticated remote code execution through improper input validation in the accesscontrol function. No patch information is currently available in the advisory.
Affected products
- MSI RadiX AXE6600 v781521
Timeline
- 2026-08-09: disclosed