Junglewise Threat Intelligence

CVE-2026-71986: MSI Radix AXE6600 command injection in DMZ function

CVE-2026-71986 · Severity: critical · CVSS 9.8 · Published 2026-08-09

Technologies: MSI Radix AXE6600. Vendors: MSI.

Executive brief

The MSI Radix AXE6600 is a consumer WiFi 6E gaming router used to provide wireless connectivity in homes and offices. A command injection vulnerability in the router's DMZ (demilitarized zone) configuration function allows remote attackers to execute arbitrary commands with root privileges on the device. An attacker exploiting this flaw could take full control of the network infrastructure, potentially compromising all connected devices and intercepting network traffic.

Technical details

The vulnerability is a command injection flaw in the DMZ function of MSI Radix AXE6600 firmware version v781521. The affected component fails to properly validate or sanitize user input before passing it to a system command execution context, allowing an attacker to inject arbitrary shell commands. The vulnerability is remotely exploitable over the network without requiring authentication or user interaction. A successful exploit grants the attacker root-level code execution on the router, enabling complete device compromise, malware installation, and potential pivot attacks into the network. Patches or fixed firmware versions are not yet confirmed to be available based on available public information.

Affected products

  • MSI Radix AXE6600 v781521

Timeline

  • 2026-08-09: disclosed

References

Related threats