Impact
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function, allowing remote attackers to execute arbitrary commands on the device and obtain root privileges. This flaw, classified as CWE‑78, enables attackers to inject malicious code through the web interface and control the underlying operating system.
Affected Systems
The vulnerability affects MSI Radix AXE6600 Wi‑Fi routers running firmware v781521. Users of this specific firmware revision should identify if their device is running the affected version.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, yet the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely via the router’s web management interface, potentially compromising all devices connected to the network. Given the high impact and remote attack vector, the risk is significant.
OpenCVE Enrichment