CVE-2026-71988: MSI Radix AXE6600 v781521 Command Injection via portFw function
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71988?
The severity of CVE-2026-71988 is critical with a score of 9.8.
How do I fix CVE-2026-71988?
To fix CVE-2026-71988, update the MSI Radix AXE6600 router firmware to the latest version provided by MSI.
What type of vulnerability is CVE-2026-71988?
CVE-2026-71988 is categorized as an OS Command Injection vulnerability.
Who can exploit CVE-2026-71988?
Remote attackers can exploit CVE-2026-71988 to execute arbitrary commands on the affected device.
In which firmware version is CVE-2026-71988 found?
CVE-2026-71988 is found in the MSI Radix AXE6600 router firmware version v781521.