MSI Radix AXE6600 Router Telnet Command Injection (CVE-2026-71991)
First seen Aug 11, 2026 · Updated Aug 11, 2026 · CVSS 9.8
A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 router firmware v781521, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This flaw could be leveraged to fully compromise home and small-office network infrastructure, enabling traffic interception, lateral movement, or botnet recruitment.
Technical Analysis
The vulnerability resides in the TelnetSSH function that handles Telnet configuration parameters on the MSI Radix AXE6600 router, where insufficient input sanitization allows attacker-controlled input to be passed directly to a system shell. Exploitation requires network access to the Telnet configuration interface and does not require prior authentication, enabling remote code execution with root privileges (CVSS 9.8). Once exploited, attackers gain full control of the underlying Linux-based OS, allowing firmware modification, persistent backdoor installation, or use of the device as a pivot point for further network intrusion. Organizations that route AI agent traffic, RAG pipeline data, or LLM API calls through compromised network infrastructure could face man-in-the-middle interception of API keys, prompts, or model outputs, making this router-level compromise indirectly relevant to agent security postures relying on network-layer trust.
Affected Systems
MSI Radix AXE6600 router, firmware version v781521, specifically the Telnet configuration interface (TelnetSSH function)
Indicators of Compromise
- No specific IOCs published; monitor for unauthorized Telnet configuration changes, unexpected root shell access, or anomalous outbound connections from MSI Radix AXE6600 devices
Remediation Steps
- 1
Apply Firmware Update
Check MSI's support site for a patched firmware release addressing CVE-2026-71991 and apply immediately.
- 2
Disable Telnet Interface
Disable the Telnet configuration interface entirely if not required, favoring SSH or HTTPS-based management.
- 3
Restrict Network Access
Limit access to router management interfaces to trusted internal networks only, blocking WAN-facing exposure of Telnet ports.
- 4
Network Segmentation
Segment IoT and network infrastructure devices from critical systems, including hosts running AI agent or LLM pipeline workloads, to limit blast radius from a router compromise.
- 5
Monitor for Indicators
Review router logs for unauthorized configuration changes, unexpected privilege escalations, or unfamiliar processes running with root access.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.