CVE-2026-71987: MSI Radix AXE6600 v781521 Command Injection via alg function
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MSI Radix AXE6600 router firmwareto a version that resolves this vulnerability.Fixed in v781521
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71987?
CVE-2026-71987 has a severity rating of critical with a score of 9.8.
How do I fix CVE-2026-71987?
To fix CVE-2026-71987, users should update their MSI Radix AXE6600 router firmware to the latest version provided by MSI.
What type of vulnerability is CVE-2026-71987?
CVE-2026-71987 is an OS command injection vulnerability that allows remote attackers to execute arbitrary commands.
What devices are affected by CVE-2026-71987?
CVE-2026-71987 affects the MSI Radix AXE6600 router firmware version v781521.
Can CVE-2026-71987 be exploited remotely?
Yes, CVE-2026-71987 can be exploited remotely through the ALG function of the affected router.