CVE-2026-71991

MSI · Radix AXE6600

A command injection vulnerability in the TelnetSSH function of the MSI Radix AXE6600 router allows unauthenticated remote attackers to execute arbitrary system commands with root privileges.

Executive summary

The MSI Radix AXE6600 router contains a critical command injection vulnerability that permits unauthenticated remote attackers to achieve full system compromise.

Vulnerability

This is an OS command injection vulnerability (CWE-78) located in the TelnetSSH function used for Telnet configuration. The vulnerability does not require authentication, allowing an attacker to inject malicious shell commands directly into the system execution pipeline to gain root-level access.

Business impact

Successful exploitation of this vulnerability results in full administrative control over the affected network device. Given the CVSS score of 9.8, this poses a severe risk, as an attacker could intercept network traffic, pivot into internal network segments, or deploy persistent malware, leading to significant data breaches and total loss of device integrity.

Remediation

Immediate Action: Check the MSI support website for the latest firmware release and apply the update immediately to the affected Radix AXE6600 units.

Proactive Monitoring: Inspect system logs for unusual Telnet configuration activity and monitor for unauthorized outbound connections originating from the router.

Compensating Controls: Disable Telnet services on the device if they are not strictly required for operations, and restrict management interface access to trusted administrative IP addresses via firewall rules.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The critical nature of this vulnerability necessitates immediate attention. Administrators must prioritize updating the device firmware to the latest version provided by MSI. If an update is not immediately feasible, ensure that administrative interfaces are not reachable from the public internet to mitigate the risk of remote exploitation.