Impact
The vulnerability in the wps.cgi interface of MSI Radix AXE6600 firmware v781521 permits attackers to inject arbitrary commands through unsanitized parameters pin2g, pin5g, or pin6g. This is a classic instance of command injection (CWE-78), allowing execution of any shell command with full root privileges on the device. The scope of impact is system-wide, compromising confidentiality, integrity, and availability of the router and any networks connected to it.
Affected Systems
The affected product is the MSI Radix AXE6600 Wi‑Fi 6E gaming router running firmware version v781521. No other vendors or product lines are listed as affected.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score is not provided, so the current exploitation probability is unknown, but the lack of a KEV listing does not rule out active attacks. The likely attack vector is remote over the network via HTTP requests to wps.cgi, and the vulnerability can be triggered without authentication if WPS is enabled and accessible.
OpenCVE Enrichment