CVE-2025-61939

8.8

Columbia Weather Systems · MicroServer

A vulnerability in the Columbia Weather Systems MicroServer allows an attacker to redirect an outbound reverse SSH connection to an attacker controlled device.

Executive summary

An unauthenticated remote attacker can intercept and redirect outbound SSH traffic from the Columbia Weather Systems MicroServer, potentially leading to full system compromise.

Vulnerability

This flaw involves the improper restriction of communication channels (CWE-923), where an unused function initiates a reverse SSH connection without mutual authentication. An attacker with local network access and the ability to perform DNS spoofing can redirect this connection to a malicious endpoint.

Business impact

The exploitation of this vulnerability allows for unauthorized access to sensitive internal systems, effectively bypassing perimeter defenses. Given the CVSS score of 8.8, this represents a high risk of total system compromise, including the potential for data exfiltration and loss of control over the affected industrial hardware.

Remediation

Immediate Action: Update the MicroServer firmware to version MS_4.1_14142 or later by contacting Columbia Weather Systems support directly.

Proactive Monitoring: Monitor network traffic for unexpected outbound SSH connections and review DNS query logs for signs of spoofing or redirection attempts.

Compensating Controls: Implement strict network segmentation and egress filtering to prevent unauthorized outbound SSH connections from the MicroServer to external domains.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention, particularly for environments where the MicroServer manages critical infrastructure. Administrators must contact the vendor to obtain the required firmware update and apply it as soon as possible to prevent potential interception of sensitive SSH traffic.

Sources

Originally found and disclosed by UsrPacific/Columbia Weather Systems reported these vulnerabilities to CISA., per the CVE Program record.