Sceawere

Vulnerability Detail

CVE-2026-71991UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MSI Radix AXE6600 Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
MSI
Product
Radix AXE6600
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-09T00:16:48.270Z",
  "pubdate": "2026-08-09T00:16:48.270Z",
  "executiveSummary": "The MSI Radix AXE6600 router running firmware version v781521 is susceptible to a critical command injection vulnerability. This security defect resides within the TelnetSSH function utilized for managing Telnet configuration settings. The flaw enables remote unauthenticated or privileged attackers to inject arbitrary operating system commands directly through the Telnet configuration interface. Successful exploitation of this vulnerability results in remote code execution with complete root privileges over the underlying system, severely compromising the integrity, confidentiality, and availability of the affected networking device. Given that the vulnerability exposes administrative control capabilities, malicious actors can leverage this flaw to fully subvert the router, establish persistent backdoors, intercept network traffic, or pivot further into internal network segments. Exploitation requires interaction with the device's management interfaces exposed over the network. Remediation relies strictly on vendor-supplied firmware updates or restricting administrative access to trusted internal segments until a patch is applied.",
  "technicalDetails": "The vulnerability is classified as a command injection flaw stemming from improper sanitization and validation of user-supplied input handled by the TelnetSSH function within the device firmware. Specifically, the affected software component processes parameters submitted via the Telnet configuration interface and passes them directly to underlying system shell execution routines without adequate escaping or filtering.\nThe attack flow begins when an adversary interacts with the Telnet configuration interface exposed by the MSI Radix AXE6600 router. By supplying specially crafted payloads containing shell metacharacters alongside standard configuration parameters, the attacker can break out of the intended application logic and append arbitrary system commands. Because the application executes these routines with elevated privileges, the injected payload is evaluated and executed by the underlying operating system shell with root privileges.\nThe root cause of this vulnerability lies in insecure inter-process communication or direct system call invocation where external input is concatenated into command strings rather than utilizing safe application programming interfaces that segregate arguments from executable binaries. The vulnerable component is the TelnetSSH function handling Telnet configuration routines in firmware version v781521.\nRegarding exploitation requirements, the attacker must be able to reach the vulnerable configuration interface over the network. Depending on the device's deployment configuration, this may be exposed locally on the LAN or improperly exposed to the WAN interface. Successful execution does not inherently require complex prerequisite cryptographic material if input parameters are processed without session validation or if the interface is exposed prior to authentication boundaries. The payload behavior involves executing arbitrary shell commands, allowing attackers to spawn reverse shells, modify system binaries, disable security controls, or extract sensitive system configurations. The ultimate post-exploitation impact is total system compromise, yielding root privileges and permitting persistent unauthorized control over the affected routing hardware."
}
CVE-2026-71991: MSI Radix AXE6600 Command Injection (CRITICAL Severity, CVSS: 9.8) - Sceawere