VYPR
Vendor

MSI

Products
20
CVEs
40
Across products
50
Status
Private

Products

20

Recent CVEs

40
View all 40 CVEs →
  • CVE-2021-27965CriMar 5, 2021
    risk 0.65cvss 9.8epss 0.12

    The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IOCTL request.

  • CVE-2026-71993CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and…

  • CVE-2026-71992CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and…

  • CVE-2026-71991CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability…

  • CVE-2026-71990CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through…

  • CVE-2026-71989CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute…

  • CVE-2026-71988CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute…

  • CVE-2026-71987CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute…

  • CVE-2026-71986CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute…

  • CVE-2026-71985CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol…

  • CVE-2026-71984CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and…

  • CVE-2026-71983CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit…

  • CVE-2022-31877HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.

  • CVE-2020-17382HigOct 2, 2020
    risk 0.54cvss 7.8epss 0.02

    The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).

  • CVE-2025-27813HigApr 10, 2025
    risk 0.53cvss 8.1epss 0.00

    MSI Center before 2.0.52.0 has Missing PE Signature Validation.

  • CVE-2025-27812HigApr 10, 2025
    risk 0.53cvss 8.1epss 0.00

    MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.

  • CVE-2019-16098HigSep 11, 2019
    risk 0.52cvss 7.8epss 0.18

    The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and…

  • CVE-2024-3745HigMay 18, 2024
    risk 0.51cvss 7.8epss 0.00

    MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads to triggering vulnerabilities like CVE-2024-1443 and CVE-2024-1460 from a low privileged user.

  • CVE-2021-32415HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    EXEMSI MSI Wrapper Versions prior to 10.0.50 and at least since version 6.0.91 will introduce a local privilege escalation vulnerability in installers it creates.

  • CVE-2022-38532HigSep 19, 2022
    risk 0.51cvss 7.8epss 0.00

    Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralServer.exe. This vulnerability allows attackers to escalate privileges via running a crafted executable.