External risk intelligence

MSI Radix AXE6600 Command Injection via Telnet Configuration

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71991

The vulnerability exists in a consumer router's Telnet configuration interface. While Telnet is typically an internal management protocol, router management interfaces are frequently exposed to the public internet by users or misconfiguration, making this a commonly reachable service in the context of edge networking appliances.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a command injection vulnerability in the Telnet configuration function of certain MSI Radix AXE6600 router firmware. The issue allows remote attackers to execute arbitrary commands and gain root privileges on the device, posing a significant risk if the Telnet interface is accessible.

  • Routers can be remotely commanded by attackers.
  • It impacts network security and device control.
  • Verify if this router is deployed and accessible externally.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by reaching the router's Telnet configuration interface over the network. Once accessed, they can inject malicious commands through the TelnetSSH function, potentially gaining full control of the device with root privileges.

  • Remote network access to the device.
  • Interaction with the Telnet configuration interface.
  • Risk of arbitrary command execution and root access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow attackers to execute arbitrary commands on the affected router, potentially leading to full system compromise. This is possible when the Telnet configuration interface is accessible.

  • System commands and configuration.
  • Via accessible Telnet configuration interface.
  • Attackers gain root privileges on the system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical command injection vulnerability in MSI Radix AXE6600 router firmware impacts consumer-grade networking devices, likely managed by individual owners or potentially by network infrastructure teams in small businesses. The first practical step is to identify all instances of this router model, determine if its Telnet interface is exposed externally or used for configuration, and then assess its business criticality before planning remediation.

  • Identify affected devices and exposure.
  • Confirm accountable owner for remediation.
  • Plan risk-based mitigation or patching.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the MSI Radix AXE6600 router?

The MSI Radix AXE6600 is a tri-band Wi-Fi 6E gaming router designed to manage high-speed internet traffic for home and small office networks. It acts as a gateway between local devices and the internet, providing networking features such as wireless connectivity, traffic routing, and administrative management functions like Telnet for remote configuration.

What does command injection mean for CVE-2026-71991?

This vulnerability, classified as CWE-78, occurs when a program incorrectly processes user-supplied input before executing it as a system command. In this case, the router's Telnet configuration function fails to filter malicious input, allowing an attacker to insert and run their own unauthorized instructions with root-level control over the device.

How can an attacker trigger this vulnerability?

An attacker triggers the bug by reaching the router's Telnet configuration interface over a network connection and sending specially crafted commands through the TelnetSSH function. This vulnerability is not triggered by normal wireless traffic or general web browsing; it specifically requires interaction with the Telnet administrative interface.

Is my device at risk if it is not exposed to the internet?

Halo Surface Signal indicates that while the Telnet interface is primarily an internal management tool, the risk depends heavily on how the router is deployed. If the interface is not reachable from the public internet, the attack surface is significantly smaller, though internal actors or compromised devices on the local network could still potentially reach it.

What should I do if I use this router?

Start by locating all MSI Radix AXE6600 units in your environment and checking if Telnet management is enabled. Since this function allows remote command execution, you should prioritize disabling the Telnet interface immediately if it is not required for your operations, then look for official firmware updates from MSI to resolve the underlying weakness.

References