criticalOther

MSI Radix AXE6600 Router Telnet Command Injection (CVE-2026-71991)

First seen Aug 11, 2026 · Updated Aug 11, 2026 · CVSS 9.8

routercommand-injectiontelnetfirmwarerceiotnetwork-device

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 router firmware v781521, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This flaw could be leveraged to fully compromise home and small-office network infrastructure, enabling traffic interception, lateral movement, or botnet recruitment.

Technical Analysis

The vulnerability resides in the TelnetSSH function that handles Telnet configuration parameters on the MSI Radix AXE6600 router, where insufficient input sanitization allows attacker-controlled input to be passed directly to a system shell. Exploitation requires network access to the Telnet configuration interface and does not require prior authentication, enabling remote code execution with root privileges (CVSS 9.8). Once exploited, attackers gain full control of the underlying Linux-based OS, allowing firmware modification, persistent backdoor installation, or use of the device as a pivot point for further network intrusion. Organizations that route AI agent traffic, RAG pipeline data, or LLM API calls through compromised network infrastructure could face man-in-the-middle interception of API keys, prompts, or model outputs, making this router-level compromise indirectly relevant to agent security postures relying on network-layer trust.

Affected Systems

MSI Radix AXE6600 router, firmware version v781521, specifically the Telnet configuration interface (TelnetSSH function)

Indicators of Compromise

  • No specific IOCs published; monitor for unauthorized Telnet configuration changes, unexpected root shell access, or anomalous outbound connections from MSI Radix AXE6600 devices

Remediation Steps

  1. 1

    Apply Firmware Update

    Check MSI's support site for a patched firmware release addressing CVE-2026-71991 and apply immediately.

  2. 2

    Disable Telnet Interface

    Disable the Telnet configuration interface entirely if not required, favoring SSH or HTTPS-based management.

  3. 3

    Restrict Network Access

    Limit access to router management interfaces to trusted internal networks only, blocking WAN-facing exposure of Telnet ports.

  4. 4

    Network Segmentation

    Segment IoT and network infrastructure devices from critical systems, including hosts running AI agent or LLM pipeline workloads, to limit blast radius from a router compromise.

  5. 5

    Monitor for Indicators

    Review router logs for unauthorized configuration changes, unexpected privilege escalations, or unfamiliar processes running with root access.

CVE / Advisory IDs

CVE-2026-71991

Industries Most Exposed

consumer electronicssmall business/home office networkingtelecommunicationscritical infrastructure (via network dependency)

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.