Junglewise Threat Intelligence

CVE-2026-71985: MSI RadiX AXE6600 command injection in accesscontrol function

CVE-2026-71985 · Severity: critical · CVSS 9.8 · Published 2026-08-09

Technologies: MSI Radix AXE6600. Vendors: MSI.

Executive brief

The MSI RadiX AXE6600 is a WiFi 6E gaming router used to provide wireless connectivity in homes and small businesses. A command injection vulnerability in the router's access control firmware allows remote attackers to execute arbitrary commands with root privileges, potentially giving an attacker complete control over the device and any data passing through it.

Technical details

The vulnerability is a command injection flaw in the accesscontrol function of the MSI RadiX AXE6600 router firmware (version v781521). An attacker can exploit this vulnerability remotely to execute arbitrary shell commands on the device, obtaining root-level access to the underlying system. The vulnerability allows unauthenticated remote code execution through improper input validation in the accesscontrol function. No patch information is currently available in the advisory.

Affected products

  • MSI RadiX AXE6600 v781521

Timeline

  • 2026-08-09: disclosed

References

Related threats