Impact
An attacker can inject commands into the dmz function of MSI Radix AXE6600 routers running firmware v781521. The injected payload is executed by the system shell, granting the attacker unrestricted root access to the device. This allows the attacker to modify firmware, intercept or redirect network traffic, or use the router as a foothold for further attacks. The weakness is classified as CWE-78, indicating unsafe native command execution due to insufficient input validation.
Affected Systems
The vulnerability affects MSI Radix AXE6600 Wi‑Fi 6E Tri‑Band Gaming Routers with firmware version v781521. No other products or firmware versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as Critical. The EPSS score of 2% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the router’s management interface, specifically the dmz function exposed through the web interface. If an attacker succeeds, they gain full root control over the device, compromising confidentiality, integrity, and availability of the router and potentially the connected network.
OpenCVE Enrichment