Impact
The MSI Radix AXE6600 firmware version v781521 contains a CWE‑78 command injection flaw in the macfilter function, allowing a remote attacker to inject and execute arbitrary operating‑system commands on the device. This escalates privileges to root, granting full control over the router’s underlying system and enabling attackers to modify traffic, install persistence mechanisms, or compromise connected devices.
Affected Systems
MSI Radix AXE6600 WiFi 6E Tri‑Band Gaming Router running firmware version v781521 is affected. No other firmware revisions are listed as vulnerable in the CNA data.
Risk and Exploitability
The CVSS score of 9.3 indicates the vulnerability is severe, with the potential for complete system takeover. The EPSS score of 1% indicates a very small but non-zero probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited, but the risk remains high due to its remote nature and the fact that any user who can send requests to the macfilter interface can trigger a full compromise. Attackers would likely target the router from within the local network, where the macfilter API is exposed, and could achieve root access by crafting an injection payload.
OpenCVE Enrichment