Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a command injection vulnerability in the Telnet configuration function of certain MSI Radix AXE6600 router firmware. The issue allows remote attackers to execute arbitrary commands and gain root privileges on the device, posing a significant risk if the Telnet interface is accessible.
- Routers can be remotely commanded by attackers.
- It impacts network security and device control.
- Verify if this router is deployed and accessible externally.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by reaching the router's Telnet configuration interface over the network. Once accessed, they can inject malicious commands through the TelnetSSH function, potentially gaining full control of the device with root privileges.
- Remote network access to the device.
- Interaction with the Telnet configuration interface.
- Risk of arbitrary command execution and root access.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow attackers to execute arbitrary commands on the affected router, potentially leading to full system compromise. This is possible when the Telnet configuration interface is accessible.
- System commands and configuration.
- Via accessible Telnet configuration interface.
- Attackers gain root privileges on the system.
Operational Fix
Recommended remediation, mitigation, and detection steps
The critical command injection vulnerability in MSI Radix AXE6600 router firmware impacts consumer-grade networking devices, likely managed by individual owners or potentially by network infrastructure teams in small businesses. The first practical step is to identify all instances of this router model, determine if its Telnet interface is exposed externally or used for configuration, and then assess its business criticality before planning remediation.
- Identify affected devices and exposure.
- Confirm accountable owner for remediation.
- Plan risk-based mitigation or patching.