External risk intelligence

MSI Radix AXE6600 Command Injection via TelnetSSH Function

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71990

The vulnerability resides in the SSH configuration interface of a consumer-grade router. While SSH is typically intended for administrative access, routers of this type are frequently managed remotely or misconfigured to expose management interfaces to the internet, making them a common target for remote access and potential exposure.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in MSI Radix AXE6600 router firmware that could allow remote attackers to execute arbitrary commands and gain root privileges. The issue lies within the TelnetSSH function used for SSH configuration. At a high level, this could potentially compromise the affected devices if their management interfaces are accessible.

  • Commands can be injected remotely.
  • Affects network device security and management.
  • Confirm relevance and potential exposure of affected devices.

Attack Path

How an attacker could exploit the issue

An attacker could remotely exploit this vulnerability by interacting with the SSH configuration interface of the MSI Radix AXE6600 router. This interaction allows them to inject commands, potentially leading to the execution of arbitrary code with root privileges on the affected device.

  • No authentication required to access.
  • Triggered through the SSH configuration interface.
  • Allows arbitrary command execution and root access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow remote attackers to execute arbitrary commands on the affected router when the TelnetSSH function is used for SSH configuration. This could lead to unauthorized control of the device.

  • Device control and system access.
  • Exploitation via SSH configuration interface.
  • Root privileges on the underlying system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The affected MSI Radix AXE6600 router firmware, particularly its TelnetSSH function, presents a critical command injection vulnerability. Given its network-facing nature and the potential for remote exploitation, infrastructure and network security teams are likely responsible for managing this device. The immediate priority is to identify all deployed instances of this router, assess their exposure to the internet, and determine their business criticality to inform a risk-based remediation plan.

  • Ownership: Network and security teams.
  • Verify first: Internet reachability and criticality.
  • Action: Plan for firmware update or access control.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the MSI Radix AXE6600?

The MSI Radix AXE6600 is a high-performance, WiFi 6E tri-band gaming router. It provides wireless connectivity and network routing for home and small office environments. Users rely on it to manage local network traffic, connect devices to the internet, and configure security settings through built-in administrative interfaces.

What does command injection mean for CVE-2026-71990?

This vulnerability is classified as CWE-78, or OS Command Injection. It means the router software fails to properly filter user input within its TelnetSSH configuration function. An attacker can use this flaw to 'inject' their own unauthorized commands, which the system then executes with root-level privileges, effectively granting the attacker full control over the device.

How is this command injection triggered?

The vulnerability is triggered by interacting with the specific TelnetSSH function used for SSH configuration on the device. Because the function does not require authentication, an attacker can reach the interface and supply malicious commands directly. This bug is specifically tied to the SSH configuration process; normal network traffic passing through the router is not the trigger.

Why should I care about this router's internet exposure?

According to Halo Surface Signal, this vulnerability is particularly concerning because consumer-grade routers are often misconfigured or intentionally set to allow remote management over the internet. If your device's configuration interface is reachable from the public web, it is much more likely to be accessed by unauthorized parties, making it a high-priority target for remote exploitation.

What are the first steps to secure my device?

Start by identifying every MSI Radix AXE6600 instance in your environment and checking if its administrative or SSH interfaces are accessible from the internet. If they are exposed, restrict access to these management interfaces immediately. Follow up by coordinating with your network team to obtain and apply the necessary firmware updates from MSI once they are available.

References