PatchSiren cyber security CVE debrief
CVE-2026-53876 Micro-Star International Co., Ltd. CVE debrief
The RadiX AX6600 WiFi 6 Tri-Band Gaming Router is vulnerable to an OS command injection attack. This vulnerability, tracked as CVE-2026-53876, allows an administrator logged into the web console to execute arbitrary commands with root privileges. The vulnerability has a CVSS score of 8.6, indicating a high severity level. Users with access to the web console as administrators are at risk. Immediate action is required to mitigate this vulnerability.
- Vendor
- Micro-Star International Co., Ltd.
- Product
- RadiX AX6600 WiFi 6 Tri-Band Gaming Router
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and users of the RadiX AX6600 WiFi 6 Tri-Band Gaming Router, especially those with administrative access to the web console, should be aware of this vulnerability and take necessary precautions.
Technical summary
CVE-2026-53876 is an OS command injection vulnerability in the RadiX AX6600 WiFi 6 Tri-Band Gaming Router. It allows an administrator logged into the web console to execute arbitrary commands with root privileges due to improper input validation or sanitization. The vulnerability's CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X, indicating a high severity level.
Defensive priority
High
Recommended defensive actions
- Update the RadiX AX6600 WiFi 6 Tri-Band Gaming Router firmware to the latest version if available.
- Limit access to the web console to only necessary personnel.
- Implement strong authentication and authorization mechanisms for web console access.
- Regularly monitor the router for suspicious activity.
- Consider using a web application firewall to detect and prevent attacks.
- Review and restrict the use of administrative privileges.
- Refer to the vendor's support page for more information: [ref-5](https://www.msi.com/Networking/RadiX-AX6600-WiFi-6-Tri-Band-Gaming-Router/support).
Evidence notes
The information provided is based on data from the National Vulnerability Database (NVD) and other reliable sources. The CVE record and NVD detail pages provide further information on this vulnerability.
Official resources
CVE-2026-53876 was published on 2026-06-17T13:20:49.537Z and modified on 2026-06-17T16:18:00.113Z.