Impact
MSI Radix AXE6600 firmware version v781521 contains a command injection flaw in the openvpn function that allows a remote attacker to execute arbitrary commands with root privileges on the device. The flaw is triggered through the macfilter mechanism and can be used to run malicious system commands, effectively compromising the entire router.
Affected Systems
MSI Radix AXE6600 Wi‑Fi routers running firmware version v781521 are affected. No other firmware releases or product lines are listed as vulnerable.
Risk and Exploitability
The CVSS score of 9.3 reflects high severity and full system compromise potential, while the EPSS score of 2% indicates a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the openvpn service remotely by sending a crafted macfilter request to inject commands, requiring network connectivity to the router's administrative interface or VPN capability.
OpenCVE Enrichment