Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MSI Radix AXE6600 firmware v781521 contains a command injection flaw in the TelnetSSH function used for SSH configuration. The vulnerability enables attackers to inject and execute arbitrary shell commands with root privileges on the device, effectively allowing full control of the router. This flaw is mapped to CWE‑78, indicating an unsafe execution of system commands.

Affected Systems

MSI Radix AXE6600 routers running firmware version v781521 are impacted. No other versions or vendors are listed.

Risk and Exploitability

With a CVSS score of 9.3 the flaw is considered critical. The EPSS score is 1% and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves remote users accessing the SSH configuration interface; by supplying crafted input to the TelnetSSH command, an attacker can execute arbitrary commands and gain full system privileges.

Generated by OpenCVE AI on August 9, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MSI Radix AXE6600 to a firmware release that resolves the TelnetSSH command injection flaw.
  • Disable the TelnetSSH function or the SSH configuration interface if not required for device management.
  • Restrict SSH access to trusted IP addresses or internal networks, and enforce strong authentication.
  • Monitor SSH logs for suspicious activity and enforce rate limiting on configuration changes.

Generated by OpenCVE AI on August 9, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi radix Axe6600
Vendors & Products Msi
Msi radix Axe6600

Sat, 08 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Msi Radix Axe6600
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-11T17:52:14.278Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71990

cve-icon Vulnrichment

Updated: 2026-08-11T17:47:58.651Z

cve-icon NVD

Status : Received

Published: 2026-08-09T00:16:48.130

Modified: 2026-08-11T18:18:23.150

Link: CVE-2026-71990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:28:02Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')