Impact
The MSI Radix AXE6600 firmware version v781521 contains a command injection flaw in the macfilter function that allows a remote attacker to inject and execute arbitrary operating‑system commands on the device. The vulnerability escalates privileges to root, providing full control over the router’s underlying system and allowing the attacker to perform any action the device owner can, including modifying traffic, installing persistence mechanisms, or compromising connected devices.
Affected Systems
MSI Radix AXE6600 WiFi 6E Tri‑Band Gaming Router running firmware version v781521 is affected. No other firmware revisions are listed as vulnerable in the CNA data.
Risk and Exploitability
The CVSS score of 9.3 indicates the vulnerability is severe, with the potential for complete system takeover. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited, but the risk remains high due to its remote nature and the fact that any user who can send requests to the macfilter interface can trigger a full compromise. Attackers would likely target the router from within the local network, where the macfilter API is exposed, and could achieve root access by crafting an injection payload.
OpenCVE Enrichment