<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Radix AXE6600 (V781521) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/radix-axe6600-v781521/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 08 Aug 2026 23:42:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/radix-axe6600-v781521/feed.xml" rel="self" type="application/rss+xml"/><item><title>Command Injection in MSI Radix AXE6600 Router</title><link>https://feed.craftedsignal.io/briefs/2026-08-msi-router-command-injection/</link><pubDate>Sat, 08 Aug 2026 23:42:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-msi-router-command-injection/</guid><description>The MSI Radix AXE6600 router firmware version v781521 is vulnerable to remote command injection via the wps.cgi interface, allowing unauthenticated attackers to execute arbitrary commands with root privileges.</description><content:encoded><![CDATA[<p>The MSI Radix AXE6600 router running firmware version v781521 contains a critical command injection vulnerability in its web-based management interface. The vulnerability exists within the wps.cgi file, which fails to properly sanitize user-supplied input provided via the pin2g, pin5g, or pin6g parameters. An unauthenticated remote attacker can supply malicious payloads to these parameters to execute arbitrary commands on the underlying operating system. Because the web service operates with high privileges, successful exploitation results in full root access to the device. This poses a significant risk to the integrity and confidentiality of the network, as the compromised router can be used to facilitate man-in-the-middle attacks, exfiltration, or further lateral movement into the internal network. Defenders should monitor for anomalous HTTP requests targeting this specific CGI endpoint.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-71983 allows an attacker to achieve unauthenticated remote code execution with root-level privileges on the target router. This provides full control over the gateway device, enabling the attacker to intercept or modify all traffic traversing the device, pivot into the local area network, or persist across reboots.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update the firmware of all MSI Radix AXE6600 routers to the latest available version provided by the manufacturer to remediate CVE-2026-71983.</li>
<li>Restrict access to the router web management interface (port 80/443) so that it is only accessible from trusted administrative IP addresses rather than the internet.</li>
<li>Monitor perimeter firewall and proxy logs for HTTP GET or POST requests directed at /wps.cgi that contain suspicious characters (such as semicolons, pipes, or backticks) within the pin2g, pin5g, or pin6g parameters.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>