Impact
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function, allowing remote attackers to execute arbitrary commands on the device and obtain root privileges. This flaw, classified as CWE‑78, enables attackers to inject malicious code through the web interface and control the underlying operating system.
Affected Systems
The vulnerability affects MSI Radix AXE6600 Wi‑Fi routers running firmware v781521. Users of this specific firmware revision should identify if their device is running the affected version.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, the EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the router’s web management interface, inferred from the fact that attackers can exploit the urlfilter function to inject malicious commands. Attackers can remotely exploit the flaw, potentially compromising the device and all connected networks. Given the high impact and remote attack vector, the risk is significant.
OpenCVE Enrichment