CVE-2025-61939

HIGH

MicroServer - SSRF

Title source: llm
STIX 2.1

Description

An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device.

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 12.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-923
Status published
Products (1)
columbiaweather/weather_microserver_firmware < MS_4.1_14142
Published Jan 07, 2026
Tracked Since Feb 18, 2026