Summary
CVE-2026-71987 is an unauthenticated OS command injection vulnerability in the MSI Radix AXE6600 router. A remote attacker can exploit the device’s alg function to execute arbitrary commands and obtain root-level access. It is rated Critical.
Technical details
- Root cause: Improper neutralization of special elements used in an OS command (CWE-78) in the router’s
algfunction, which processes user-supplied input without adequate sanitization or validation. - Trigger conditions: No authentication and no user interaction are required; an attacker only needs network access to the device.
- Attack vector: Network (remote), with low attack complexity.
- Impact: Execution of arbitrary commands leading to root privileges on the underlying system, fully compromising confidentiality, integrity, and availability of the device.
Affected software
- MSI Radix AXE6600 router firmware version v781521 and earlier (0 through v781521).
Severity
- CVSS v3.1 base score: 9.8 (Critical) — Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0 base score: 9.3 (Critical) — Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Consult the MSI Radix AXE6600 support page for firmware updates and apply any released fixed version. At the time of disclosure no patch had been published.
- If no patch is available: Restrict network access to the router’s management interface, do not expose the device’s administrative services to the internet, and place the device behind a firewall that limits inbound access to trusted hosts.

