CVE-2025-61939
8.8Columbia Weather Systems · MicroServer
A vulnerability in the Columbia Weather Systems MicroServer allows an attacker to redirect an outbound reverse SSH connection to an attacker controlled device.
Executive summary
An unauthenticated remote attacker can intercept and redirect outbound SSH traffic from the Columbia Weather Systems MicroServer, potentially leading to full system compromise.
Vulnerability
This flaw involves the improper restriction of communication channels (CWE-923), where an unused function initiates a reverse SSH connection without mutual authentication. An attacker with local network access and the ability to perform DNS spoofing can redirect this connection to a malicious endpoint.
Business impact
The exploitation of this vulnerability allows for unauthorized access to sensitive internal systems, effectively bypassing perimeter defenses. Given the CVSS score of 8.8, this represents a high risk of total system compromise, including the potential for data exfiltration and loss of control over the affected industrial hardware.
Remediation
Immediate Action: Update the MicroServer firmware to version MS_4.1_14142 or later by contacting Columbia Weather Systems support directly.
Proactive Monitoring: Monitor network traffic for unexpected outbound SSH connections and review DNS query logs for signs of spoofing or redirection attempts.
Compensating Controls: Implement strict network segmentation and egress filtering to prevent unauthorized outbound SSH connections from the MicroServer to external domains.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate attention, particularly for environments where the MicroServer manages critical infrastructure. Administrators must contact the vendor to obtain the required firmware update and apply it as soon as possible to prevent potential interception of sensitive SSH traffic.
Sources
Originally found and disclosed by UsrPacific/Columbia Weather Systems reported these vulnerabilities to CISA., per the CVE Program record.