CVE-2025-61939

HIGH

Columbia Weather MicroServer Firmware - Reverse SSH Redirection

Title source: manual
STIX 2.1

Description

An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device.

Scores

CVSS v3 8.8
EPSS 0.0024
EPSS Percentile 15.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-923
Status published
Products (1)
columbiaweather/weather_microserver_firmware < MS_4.1_14142
Published Jan 07, 2026
Tracked Since Feb 18, 2026