Summary
CVE-2026-71989 is an unauthenticated OS command injection vulnerability in the MSI Radix AXE6600 Wi‑Fi 6E gaming router. The flaw resides in the porTrigger function of firmware version v781521 and earlier, allowing remote attackers to execute arbitrary commands and gain root privileges on the device. It is rated Critical (CVSS v4.0 9.3).
Technical details
- Root cause: The
porTriggerfunction fails to properly neutralize special elements in user-supplied input before passing it to an OS command (CWE-78). - Trigger conditions: Exploitable via the
algfunction; no authentication, privileges, or user interaction are required. - Attack vector: Network — a remote attacker sends crafted input to the affected device.
- Impact: Execution of arbitrary commands leading to root privileges on the underlying system, resulting in complete device compromise.
Affected software
- MSI Radix AXE6600 router firmware version v781521 and earlier.
Severity
- CVSS v4.0 base score: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - CVSS v3.1 base score: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade firmware to version v782418 or later, available from the MSI support page.
- If no patch: Restrict access to the router’s management and remote-administration interfaces to trusted networks only, and ensure the device is not exposed directly to the internet.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
MSI Router - Raw response body:
GRAXE66,RadiX AXE6600

