Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command injection flaw in the TelnetSSH function of the router's configuration interface, enabling an attacker to run arbitrary commands with root privileges on the underlying system. This results in a full compromise of the device, exposing the internal network to further attacks, unauthorized changes, and persistent footholds.

Affected Systems

The vulnerability affects MSI Radix AXE6600 routers with firmware version v781521. The Telnet configuration interface is the primary attack surface.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable remotely via the Telnet configuration interface; an attacker only needs network reachability to that port to inject malicious commands and gain root privileges. The potential impact is complete loss of confidentiality, integrity, and availability of the affected device and the broader network segments it manages.

Generated by OpenCVE AI on August 9, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest version that addresses the command injection flaw.
  • If a firmware update is not yet available, disable or block the Telnet port to prevent external access to the configuration interface.
  • Restrict network access to the router's administration interface and enable only secure SSH if available, ensuring that only trusted hosts can connect.

Generated by OpenCVE AI on August 9, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T23:49:27.087Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71991

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T01:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')