Impact
A command injection flaw exists in the porTrigger function of MSI Radix AXE6600 router firmware v781521. By sending specially crafted input to this function, an attacker can inject operating system commands, which are executed with root privileges on the device. This permits full compromise of the device, enabling data exfiltration, persistence, or further network attacks.
Affected Systems
MSI Radix AXE6600 routers running firmware version v781521 are affected. No other MSI products or firmware versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity, and the EPSS score of 1% indicates a low but non-zero probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers can exploit it remotely through the alg function, which is reachable over the network, thereby facilitating arbitrary command execution without local access. Given the remote attack vector and the ability to gain root, the risk is substantial.
OpenCVE Enrichment