CVE-2026-53876: OS Command Injection
RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the router's web management interface for remote access if possible; restrict administrative login to local LAN or console only. If remote administration is required, require VPN access and/or other strong access controls.
RadiX AX6600 web console administrative web console access = disabled or limited to local/managed access only - Compensating control
Block or restrict access to the router management interface at network perimeter devices: deny WAN/Internet access to the management port, allow only trusted IPs or a management VLAN, and require VPN or jump-host for remote administration.
- Operational
Audit administrative accounts and recent web-console logins; change administrator passwords and any credentials that may have been used, and monitor device logs for suspicious activity until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53876?
CVE-2026-53876 has a high severity rating of 7.2.
What type of vulnerability is documented in CVE-2026-53876?
CVE-2026-53876 is an OS command injection vulnerability.
How does CVE-2026-53876 impact the RadiX AX6600 WiFi 6 Tri-Band Gaming Router?
CVE-2026-53876 may allow arbitrary command execution with root privileges by an authenticated administrator.
Who is affected by the CVE-2026-53876 vulnerability?
Users who log in as administrators to the web console of the RadiX AX6600 router are affected by CVE-2026-53876.
How can I remediate CVE-2026-53876?
To fix CVE-2026-53876, ensure that your RadiX AX6600 firmware is updated to the latest version provided by the manufacturer.