Impact
The MSI Radix AXE6600 router firmware version v781521 contains a command injection flaw in its accesscontrol function, identified as a CWE-78 weakness. This flaw allows an attacker to inject arbitrary system commands through the function, resulting in execution with root privileges on the device’s operating system.
Affected Systems
The affected product is MSI Radix AXE6600 network appliance, specifically firmware release v781521. No other versions are listed as impacted, and no additional products or variants are mentioned in the vendor data.
Risk and Exploitability
The CVSS base score of 9.3 reflects a critical level of severity, and the vulnerability can be triggered remotely via the accesscontrol function. The EPSS score of 1% indicates a very low but non‑zero probability of exploitation, although the exact likelihood remains uncertain. The router is not listed in the CISA KEV catalog, but the high severity warrants immediate attention.
OpenCVE Enrichment