CVE-2025-66620
8.0Columbia Weather Systems · MicroServer
An unused webshell in Columbia Weather Systems MicroServer allows authenticated attackers to gain limited shell access, enabling persistence and file system modification.
Executive summary
An unused webshell vulnerability in the Columbia Weather Systems MicroServer allows attackers with administrative access to achieve unauthorized shell commands, posing a significant risk to system integrity.
Vulnerability
The flaw involves a command shell located in an externally accessible directory (CWE-553). An attacker with existing administrative access can leverage this unused webshell to gain limited shell access, facilitating persistence through reverse shells and unauthorized file system manipulation.
Business impact
Successful exploitation of this vulnerability could lead to a complete compromise of the affected device, resulting in unauthorized data modification, removal, and the establishment of persistent backdoors. Given the CVSS score of 8.0, this represents a high-severity risk that could lead to operational disruption of weather monitoring services and long term persistence for threat actors within the network.
Remediation
Immediate Action: Update the MicroServer firmware to version MS_4.1_14142 or later by contacting Columbia Weather Systems support directly via email or telephone.
Proactive Monitoring: Monitor system logs for unusual shell process spawning or unauthorized modifications to sensitive directories and configuration files.
Compensating Controls: Restrict administrative access to the MicroServer management interface to trusted internal IP addresses only, and employ network segmentation to isolate the device from external traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a clear risk to the security and integrity of the MicroServer environment. Administrators must prioritize the installation of the provided firmware update to remove the unused webshell and eliminate the command shell vector. Contacting the vendor promptly to obtain the necessary update is the most effective path to mitigating this risk.
Sources
Originally found and disclosed by UsrPacific/Columbia Weather Systems reported these vulnerabilities to CISA., per the CVE Program record.