A command injection flaw in the MSI Radix AXE6600's SSH configuration handler lets unauthenticated remote attackers execute arbitrary commands as root, carrying a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-71990 is an OS command injection vulnerability (CWE-78) in the TelnetSSH function of the MSI Radix AXE6600 router firmware. The function, used for SSH configuration, fails to sanitize input passed through the SSH configuration interface. A remote attacker can inject shell metacharacters into that interface and have arbitrary commands executed on the underlying system with root privileges.
The CVE was assigned by VulnCheck. Its NVD status is currently "Received," meaning the record has not yet completed NVD analysis.
Why It Matters
The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, describes the worst realistic case for a consumer edge device: network-reachable, low complexity, no privileges, and no user interaction required, with total loss of confidentiality, integrity, and availability. The CVSS 4.0 secondary score is 9.3 (CRITICAL).
Because exploitation yields root on the router itself, a successful attack gives an adversary control of the network perimeter: traffic interception, DNS manipulation, persistence across the LAN, and a foothold for pivoting to internal hosts. Routers are also rarely monitored and infrequently patched, which extends the useful lifetime of any compromise.
CISA KEV does not currently list this CVE. That absence is not evidence that exploitation is not occurring; KEV reflects exploitation CISA has confirmed and chosen to catalog, and consumer router compromises are frequently underreported. Treat the lack of a KEV entry as an absence of public confirmation rather than an all-clear.
What's Vulnerable
- Vendor: MSI
- Product: Radix AXE6600 (WiFi 6E Tri-Band Gaming Router)
- Affected firmware: all versions up to and including v781521
No CPE entries have been published for this CVE yet.
Patch Status
The supplied source material does not identify a fixed firmware version, vendor advisory, or specific remediation guidance. Because no KEV entry exists, there is no CISA-mandated required action or due date.
Owners should monitor the MSI Radix AXE6600 support page for firmware updates, and in the interim restrict reachability of the router's management and SSH configuration interfaces; particularly from the WAN side.