Impact
The vulnerability is a command injection flaw in the TelnetSSH function of the router's configuration interface, enabling an attacker to run arbitrary commands with root privileges on the underlying system. This results in a full compromise of the device, exposing the internal network to further attacks, unauthorized changes, and persistent footholds.
Affected Systems
The vulnerability affects MSI Radix AXE6600 routers with firmware version v781521. The Telnet configuration interface is the primary attack surface.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable remotely via the Telnet configuration interface; an attacker only needs network reachability to that port to inject malicious commands and gain root privileges. The potential impact is complete loss of confidentiality, integrity, and availability of the affected device and the broader network segments it manages.
OpenCVE Enrichment