Impact
The vulnerability resides in the firmware of MSI Radix AXE6600 routers and allows a remote attacker to inject arbitrary operating‑system commands via the alg function, leading to execution of commands with root privileges. This command‑injection weakness is identified as CWE‑78.
Affected Systems
MSI Radix AXE6600 routers running firmware version v781521 are affected. No other affected products or versions are listed.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as critical. The EPSS score of 1% indicates a low but nonzero exploitation probability, and the vulnerability is not listed in CISA KEV. The description explicitly states that remote attackers can exploit the alg function to execute arbitrary commands. If successful, an attacker gains full control over the device.
OpenCVE Enrichment