A command injection flaw in the MSI Radix AXE6600 router's Telnet configuration handler lets unauthenticated remote attackers run arbitrary commands as root, earning a CVSS 3.1 score of 9.8 (Critical).
What Is It
CVE-2026-71991 is an OS command injection vulnerability (CWE-78) in MSI Radix AXE6600 router firmware version v781521. The defect sits in the TelnetSSH function used for Telnet configuration. According to the NVD record, remote attackers can reach the Telnet configuration interface, inject malicious commands, and execute them on the affected device; obtaining root privileges on the underlying system.
The vulnerability was disclosed through VulnCheck ([email protected]) and is newly published to NVD, where it currently sits in "Received" status; meaning NVD analysts have not yet completed enrichment of the record.
Why It Matters
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 9.8, Critical. Every exploitability condition favors the attacker: network attack vector, low complexity, no privileges required, and no user interaction. A CVSS 4.0 assessment from the same source rates it 9.3 Critical with matching high confidentiality, integrity, and availability impact.
Root access on a gateway device means full control of the network boundary. There is no scope change recorded, but the compromised component is the router itself.
CISA has not added CVE-2026-71991 to the Known Exploited Vulnerabilities catalog; the supplied KEV entry is empty, so there is no confirmation of active exploitation and no KEV-mandated remediation deadline at this time.
What's Vulnerable
- Vendor: MSI
- Product: Radix AXE6600 (WiFi 6E Tri-Band Gaming Router)
- Affected version: firmware v781521; the single release named in the published record
The source data identifies v781521 by version, not a version range; it does not state that earlier or later firmware builds were tested, so their status is unknown rather than confirmed safe. No CPE configurations were published in the NVD record at the time of writing.
Patch Status
The NVD record lists no patched version and no fixed firmware release. The only vendor-side references supplied are MSI's product support page and corporate site. Until MSI publishes updated firmware, the practical mitigation implied by the vulnerable component is to restrict reachability of the Telnet configuration interface; no vendor-supplied remediation guidance is present in the source data.
Sources
- NVD, CVE-2026-71991: https://nvd.nist.gov/vuln/detail/CVE-2026-71991
- VulnCheck Advisory; MSI Radix AXE6600 v781521 command injection via TelnetSSH function: https://www.vulncheck.com/advisories/msi-radix-axe6600-v781521-command-injection-via-telnetssh-function-used-for-telnet-configuration
- MSI Radix AXE6600 Support Page: https://us.msi.com/Networking/RadiX-AXE6600-WiFi-6E-Tri-Band-Gaming-Router/support
- MSI: https://www.msi.com/