HomeSecurityMSI Radix AXE6600: Critical vulnerabilities allow root commands

MSI Radix AXE6600: Critical vulnerabilities allow root commands

MSI Radix AXE6600 routers are affected by a series of critical command injection vulnerabilities, which could allow remote attackers to execute arbitrary commands and gain root privileges. The issues are found in firmware v781521 and are listed with a CVSS score of 9.8.

MSI Radix AXE6600 critical vulnerabilities

CVE-2026-71990, CVE-2026-71991, and CVE-2026-71992 were published on August 9, 2026. The CVE Alert describe remote exploitation in the TelnetSSH and macfilter functions, without mentioning an available fix from the vendor.

See also: D-Link DWR-M961: 18 vulnerabilities allow root commands

What do the vulnerabilities in MSI Radix AXE6600 mean?

CVE-2026-71990 concerns the TelnetSSH when used to configure SSH. The description states that a remote attacker can inject malicious commands through this interface. The result is command execution on the device and possible root privileges on the underlying system.

CVE-2026-71991 concerns the same operation when configuring Telnet. Although it is a different entry point, the impact is still critical: remote execution of arbitrary commands on the MSI Radix AXE6600 and elevation of privilege. The listing also assigns a CVSS of 9.8 to the vulnerability.

In CVE-2026-71992, the vulnerable code is located in the macfilter. The CVE Alert description states that the exploit can be done remotely, with the corresponding ability to execute commands and gain root privileges. The three entries concern the same firmware, which indicates a broader issue with input control in the router settings.

MSI Radix AXE6600 command injection

Additional entry points into the firmware

The same family of issues extends to other features in firmware v781521. The entry for CVE-2026-71993 links command injection to the openvpn feature and reports remote exploitation without required privileges or user interaction. The CVE Feed also lists CVSS 9.8 and CWE-78.

The available entries also include CVE-2026-71984 to CVE-2026-71989, which target different functions, such as urlfilter, accesscontrol, dmz, alg, and portFw. The descriptions converge on the same pattern: remote command injection and root access. However, there is no single public announcement yet confirming the extent of the affected devices.

The clustering of multiple CVEs in the MSI Radix AXE6600 increases the risk for routers that are accessible from the internet. The exploit does not require user interaction according to available data, so exposure of the management interface or remote configuration services should be addressed as an immediate priority.

Particular attention is needed in home and small business networks, where the same router often aggregates wireless access, VPN, and port forwarding rules. A breach could allow changes to routing or DNS settings, creating conditions for traffic monitoring and further attacks on internal devices.

See also: TP-Link Archer AXE75: command vulnerability in OpenVPN

MSI Radix AXE6600 protection measures

What should administrators do?

Administrators using MSI Radix AXE6600 with firmware v781521 should immediately check MSI support announcements for a newer version available. Until an official fix is ​​available, remote management should be limited to trusted networks, and Telnet and SSH services should not be exposed directly to the internet.

At the same time, it is recommended to change the administrative credentials, check the active accounts and look for unexpected changes to rules, DNS, VPN and port forwarding. The presence of root privileges means that a successful compromise can affect network traffic and devices behind the router, not just the product itself.

The SecNews technical team also recommends logging management connections and temporarily isolating devices that show suspicious changes. When official firmware becomes available, installation should be done through MSI's authorized support channel and security settings should be re-checked.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: CVE-2026-15513: command injection in Wavlink WL-NU516U1

The new listings indicate that this particular firmware v781521 requires immediate evaluation by administrators. Until a clear update is released, limiting exposure, monitoring settings, and preparing for an upgrade are key risk mitigation measures.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS