Impact
The vulnerability is a command injection flaw in the portFw function of MSI Radix AXE6600 firmware v781521. Remote attackers can inject arbitrary shell commands via the alg function, potentially leading to full control of the device and root access.
Affected Systems
Affected systems include MSI Radix AXE6600 routers running firmware version v781521. No other affected versions are publicly identified.
Risk and Exploitability
The CVSS score of 9.3 classifies the issue as critical, and although the EPSS score is not available, the lack of application in the KEV registry does not mitigate the high risk. The vulnerability is exploitable remotely, likely through the router’s network interface, and could grant attackers root privileges on the underlying Linux system.
OpenCVE Enrichment