---
id: CVE-2026-71983
title: >-
  MSI Radix AXE6600 router firmware version v781521 contains a command injection
  vulnerability in the wps.cgi interface that allows remote attackers to execute
  arbitrary commands by injecting malicious input through the pin2g, pin5g, or
  pi…
summary: >-
  MSI Radix AXE6600 router firmware version v781521 contains a command injection
  vulnerability in the wps.cgi interface that allows remote attackers to execute
  arbitrary commands by injecting malicious input through the pin2g, pin5g, or
  pi…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-08-08'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71983'
references:
  - url: >-
      https://us.msi.com/Networking/RadiX-AXE6600-WiFi-6E-Tri-Band-Gaming-Router/support
    label: disclosure@vulncheck.com
  - url: 'https://www.msi.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/msi-radix-axe6600-v781521-command-injection-via-wps-cgi
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-08-09T07:33:01.225Z'
epss: 0.01621
epssPercentile: 0.75054
vendor: MSI
product: Radix AXE6600
affected:
  - radix_axe6600 <= v781521
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-08-11T01:34:19.707548Z'
---

## Overview

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
