CVE-2026-71989: MSI Radix AXE6600 v781521 Command Injection via porTrigger function
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MSI Radix AXE6600 router firmwareto a version that resolves this vulnerability.Fixed in v781521
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71989?
The severity of CVE-2026-71989 is critical with a CVSS score of 9.8.
How do I fix CVE-2026-71989?
To fix CVE-2026-71989, update your MSI Radix AXE6600 router firmware to a patched version provided by MSI.
What type of vulnerability is presented in CVE-2026-71989?
CVE-2026-71989 is an OS Command Injection vulnerability that allows remote command execution.
Who is impacted by CVE-2026-71989?
Users of the MSI Radix AXE6600 router firmware version v781521 are impacted by CVE-2026-71989.
What can attackers achieve by exploiting CVE-2026-71989?
By exploiting CVE-2026-71989, attackers can execute arbitrary commands on the affected device.