CVE-2025-64305

MEDIUM

MicroServer - Info Disclosure

Title source: llm
STIX 2.1

Description

MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.

Scores

CVSS v3 6.5
EPSS 0.0001
EPSS Percentile 0.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-313
Status published
Products (1)
Columbia Weather Systems/MicroServer < MS_4.1_14142
Published Jan 07, 2026
Tracked Since Feb 18, 2026