Impact
An attacker can exploit a command injection flaw in the dmz function of MSI Radix AXE6600 routers running firmware v781521. The flaw allows remote execution of arbitrary system commands, giving the attacker root privileges on the underlying device. By injecting commands into the dmz input field, the attacker can alter the router’s operating system, compromise network traffic, or launch further attacks. The weakness is identified as CWE-78, indicative of unsafe native command execution with insufficient input validation.
Affected Systems
The vulnerability affects MSI Radix AXE6600 Wi‑Fi 6E Tri‑Band Gaming Routers with firmware version v781521. No other products or versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as Critical, with a high likelihood of exploitation from the Internet where the router exposes the dmz function to remote users. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog, implying no known active exploit but a realistic threat if the router is reachable. Attackers would need remote network access to the device’s management interface to exploit the flaw; once successful, they gain full root control, threatening confidentiality, integrity, and availability of the network and connected devices.
OpenCVE Enrichment