Command Injection in MSI Radix AXE6600 Router
The MSI Radix AXE6600 router firmware version v781521 is vulnerable to remote command injection via the wps.cgi interface, allowing unauthenticated attackers to execute arbitrary commands with root privileges.
The MSI Radix AXE6600 router running firmware version v781521 contains a critical command injection vulnerability in its web-based management interface. The vulnerability exists within the wps.cgi file, which fails to properly sanitize user-supplied input provided via the pin2g, pin5g, or pin6g parameters. An unauthenticated remote attacker can supply malicious payloads to these parameters to execute arbitrary commands on the underlying operating system. Because the web service operates with high privileges, successful exploitation results in full root access to the device. This poses a significant risk to the integrity and confidentiality of the network, as the compromised router can be used to facilitate man-in-the-middle attacks, exfiltration, or further lateral movement into the internal network. Defenders should monitor for anomalous HTTP requests targeting this specific CGI endpoint.
Impact
Successful exploitation of CVE-2026-71983 allows an attacker to achieve unauthenticated remote code execution with root-level privileges on the target router. This provides full control over the gateway device, enabling the attacker to intercept or modify all traffic traversing the device, pivot into the local area network, or persist across reboots.
Recommendation
- Immediately update the firmware of all MSI Radix AXE6600 routers to the latest available version provided by the manufacturer to remediate CVE-2026-71983.
- Restrict access to the router web management interface (port 80/443) so that it is only accessible from trusted administrative IP addresses rather than the internet.
- Monitor perimeter firewall and proxy logs for HTTP GET or POST requests directed at /wps.cgi that contain suspicious characters (such as semicolons, pipes, or backticks) within the pin2g, pin5g, or pin6g parameters.
Immediate actions
Patch MSI Radix AXE6600 firmware to remediate CVE-2026-71983
Mitigations
Restrict management interface access
CVE-2026-71983
Detection coverage 1
Detects CVE-2026-71983 Exploitation - Command Injection in wps.cgi
criticalDetects attempted command injection targeting the wps.cgi endpoint on MSI Radix AXE6600 routers using shell metacharacters in specific parameters.
Detection queries are available on the platform. Get full rules →