top of page
perceptive_background_267k.jpg

Columbia Weather Systems MicroServer

Published:

6 January 2026 at 12:00:00

Alert date:

6 January 2026 at 20:03:30

Source:

cisa.gov

Click to open the original link from this advisory

Three high-severity vulnerabilities discovered in Columbia Weather Systems MicroServer firmware allowing attackers to redirect SSH connections, gain admin access to web portals, and obtain shell access. CVE-2025-61939 involves improper SSH connection restrictions, CVE-2025-64305 exposes cleartext secrets on SD cards, and CVE-2025-66620 provides unauthorized webshell access. All vulnerabilities affect firmware versions below MS_4.1_14142 and can be exploited by attackers with local network access. The vendor has released patches requiring direct contact with Columbia Weather Systems Support. CVSS scores range from 6.5 to 8.8, with successful exploitation potentially leading to complete system compromise. The vulnerabilities were reported by UsrPacific and affect systems deployed in the United States Information Technology sector.

Technical details

Mitigation steps:

Affected products:

Columbia Weather Systems MicroServer

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page