Impact
A command injection vulnerability exists in the porTrigger function of the MSI Radix AXE6600 router firmware v781521 (CWE-78). Attackers can supply crafted input to this function, which is processed by the underlying alg function, allowing arbitrary operating system commands to be executed with root privileges on the device. This flaw enables a remote attacker to run any command on the router’s host system.
Affected Systems
The affected system is the MSI Radix AXE6600 router running firmware version v781521. No other MSI products or firmware releases are listed as vulnerable in the advisory.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity, and the EPSS score of 2 % reflects a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely through the alg function, which is reachable over the network, making arbitrary command execution possible without local access. The impact is therefore significant due to the remote attack vector and root‑level execution.
OpenCVE Enrichment