Impact
MSI Radix AXE6600 firmware version v781521 includes a command injection flaw in the openvpn function that lets attackers run arbitrary commands with root privileges on the device. The flaw enables complete compromise of the router, allowing an attacker to modify network traffic, install malicious software, or use the device as a pivot for further attacks in the local network.
Affected Systems
MSI Radix AXE6600 Wi‑Fi routers running firmware version v781521 are affected. No other firmware releases or vendor products are listed as vulnerable.
Risk and Exploitability
The CVSS score of 9.3 reflects the potential for full system compromise. EPSS information is not available, so the exact likelihood of exploitation remains unknown, but the high severity and lack of containment mechanisms make this vulnerability a serious threat. The flaw can be exploited remotely via the openvpn service, using the macfilter method to inject malicious code—an attack path that requires network access to the router’s administrative interface or VPN capability. The vulnerability is not listed in CISA’s KEV catalog, but its features make it an attractive target for attackers.
OpenCVE Enrichment