Sceawere

Vulnerability Detail

CVE-2026-71990UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MSI Radix AXE6600 Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
MSI
Product
Radix AXE6600
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-09T00:16:48.130Z",
  "pubdate": "2026-08-09T00:16:48.130Z",
  "executiveSummary": "A command injection vulnerability exists within the firmware version v781521 of the MSI Radix AXE6600 router. Specifically, the flaw resides in the TelnetSSH function utilized for SSH configuration management. This security defect allows remote attackers to execute arbitrary system commands with elevated privileges on the underlying operating system.\nThe vulnerability poses a severe risk to confidentiality, integrity, and availability of the affected networking hardware. Successful exploitation enables an unauthorized actor to bypass standard security controls, culminating in full administrative root privileges over the compromised device. This level of access grants the attacker complete control to manipulate network traffic, intercept sensitive data, deploy persistent malware, or use the router as a pivot point for further internal network propagation.\nAttackers can leverage this vulnerability via the device's SSH configuration interface by supplying maliciously crafted inputs designed to break out of the intended application context and execute arbitrary shell commands. Given the nature of router deployments, remote accessibility through exposed management interfaces significantly heightens the overall risk profile and necessitates immediate defensive countermeasures.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient input validation and improper sanitization within the TelnetSSH function responsible for processing SSH configuration parameters in firmware version v781521 of the MSI Radix AXE6600 router. When administrative or configuration interfaces pass user-supplied data directly to system shells or underlying execution functions without proper escaping, attackers can inject arbitrary operating system commands.\nThe exploitation method relies on interacting with the SSH configuration interface exposed by the device. The attack flow initiates when an attacker crafts a malicious payload containing shell metacharacters or command separators (such as semicolons, pipe symbols, or backticks) appended to legitimate configuration parameters. Upon submission, the vulnerable TelnetSSH function processes the input string and passes the concatenated command directly to the system execution sink.\nExecution of the injected payload results in the operating system interpreting the attacker-supplied strings as native shell commands. Because the affected daemon or script typically runs with high privileges to configure system services, the injected commands inherit these elevated execution contexts, resulting in immediate root privilege escalation on the underlying system.\nThe vulnerable component is identified as the TelnetSSH function within the device's management firmware. The affected product is the MSI Radix AXE6600 router running firmware version v781521. Network exposure depends on whether the management interfaces are accessible from the local area network or exposed directly to the wider internet, with internet-facing management planes drastically reducing the prerequisite effort for remote exploitation.\nPost-exploitation impact includes complete compromise of the device firmware and operating system. With root privileges, attackers can modify firewall rules, establish persistent backdoors, capture administrative credentials, manipulate DNS settings, and execute arbitrary code to compromise any connected network segments."
}
CVE-2026-71990: MSI Radix AXE6600 Command Injection (CRITICAL Severity, CVSS: 9.8) - Sceawere