External risk intelligence

MSI Radix AXE6600 Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71985

The vulnerable product is a consumer-grade wireless router. Routers are designed to be deployed at the internet edge, and the access control function is a standard, often network-accessible management interface on such devices.

OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a command injection vulnerability found in the firmware of certain MSI Radix routers. The flaw could allow remote attackers to execute arbitrary commands, potentially granting them control over the affected device and its underlying system. Understanding the nature of this vulnerability is key to assessing potential risks.

  • Unauthenticated attackers can run their own code.
  • This impacts network security at the internet edge.
  • Assess exposure to determine relevance and impact.

Attack Path

How an attacker could exploit the issue

Attackers can target the MSI Radix AXE6600 router through its network interface, as the `accesscontrol` function is exposed externally. By sending specially crafted requests to this function, an attacker can inject and execute arbitrary commands. Successful exploitation allows the attacker to gain root-level control over the device.

  • No prior authentication needed.
  • Triggered via the `accesscontrol` function.
  • Results in arbitrary command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow remote attackers to execute arbitrary commands on the affected router. If exploited, an attacker could potentially gain root-level control of the device by exploiting the accesscontrol function.

  • Router system control
  • Remote command execution
  • Compromised network security

Operational Fix

Recommended remediation, mitigation, and detection steps

The MSI Radix AXE6600 router's firmware contains a critical command injection vulnerability. Infrastructure and security teams should prioritize identifying all deployed AXE6600 routers, assessing their internet exposure and business criticality, and confirming ownership. This information is essential for risk-based remediation planning, which may involve vendor coordination or immediate mitigation if the device is directly exposed.

  • Identify affected routers and ownership.
  • Verify internet exposure and criticality.
  • Plan remediation or mitigation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the MSI Radix AXE6600?

The MSI Radix AXE6600 is a high-performance, tri-band WiFi 6E gaming router designed to manage home or small office network traffic. It acts as the gateway between your local devices and the internet, providing wireless connectivity and managing security features like access controls.

What does command injection mean for CVE-2026-71985?

This vulnerability is classified as CWE-78, or Improper Neutralization of Special Elements used in an OS Command. Essentially, the router fails to properly filter user input sent to its 'accesscontrol' function. This allows an attacker to 'inject' their own commands, which the router then executes as if they were legitimate system instructions, potentially granting full root-level control.

How is this vulnerability triggered?

The vulnerability is triggered when an attacker sends specially crafted requests to the router's 'accesscontrol' function. Because this function is reachable over the network, it does not require an attacker to have a valid username or password to initiate the exploit. Normal, non-malicious use of the router's configuration menus does not trigger this flaw.

Why is this router considered internet-facing?

Halo Surface Signal identifies the MSI Radix AXE6600 as a consumer-grade device typically deployed at the edge of a network to connect to an ISP. Because the 'accesscontrol' function is part of the management interface and is often reachable from the wide area network, devices running this firmware are effectively exposed to remote, unauthenticated probes.

What should I do if I use this router?

First, identify if you are running the affected firmware version, v781521. Assess the device's current deployment to see if it is exposed to the public internet. Prioritize checking the official MSI support website for firmware updates or security guidance, and consider restricting administrative access to the router to trusted internal network segments until a patch is applied.

References