CVE-2026-71990
MSI · Radix AXE6600
A command injection vulnerability in the TelnetSSH function of the MSI Radix AXE6600 router allows unauthenticated remote attackers to execute arbitrary system commands via the SSH configuration interface.
Executive summary
The MSI Radix AXE6600 router is vulnerable to a critical command injection flaw that enables unauthenticated remote attackers to execute arbitrary commands with root privileges.
Vulnerability
The vulnerability exists in the TelnetSSH function responsible for SSH configuration. This is an unauthenticated OS command injection flaw that allows an attacker to bypass security controls and execute arbitrary commands, resulting in root-level access to the underlying operating system.
Business impact
With a CVSS score of 9.8, this vulnerability represents a maximum-severity threat to business operations. Exploitation allows an attacker to fully compromise the router, which can be leveraged to conduct man-in-the-middle attacks, exfiltrate sensitive network traffic, or serve as a permanent foothold for further unauthorized access into the internal environment.
Remediation
Immediate Action: Immediately apply the latest firmware update provided by MSI to resolve the command injection flaw.
Proactive Monitoring: Review SSH configuration logs for irregular access attempts and monitor for any anomalous process execution patterns on the device.
Compensating Controls: Restrict SSH access to specific management workstations and ensure the device is not accessible via the public internet.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a high risk of unauthorized system access and must be addressed with urgency. Apply the vendor-supplied firmware update as soon as it becomes available and verify that management interfaces are properly secured against external access.