Impact
MSI Radix AXE6600 firmware v781521 contains a command injection flaw in the TelnetSSH function used for SSH configuration. The vulnerability enables attackers to inject and execute arbitrary shell commands with root privileges on the device, effectively allowing full control of the router. This flaw is mapped to CWE‑78, indicating an unsafe execution of system commands.
Affected Systems
MSI Radix AXE6600 routers running firmware version v781521 are impacted. No other versions or vendors are listed.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is considered critical. The EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector involves remote users accessing the SSH configuration interface; by supplying crafted input to the TelnetSSH command, an attacker can execute arbitrary commands and gain full system privileges.
OpenCVE Enrichment