Columbiaweather
Columbiaweather Weather Microserver Firmware: vulnerabilidades y CVE
Columbiaweather Weather Microserver Firmware tiene 8 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-66620 | Alta (8.6) | 0.46% | — | 7 ene 2026 | An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited shell access, enabling persistence… |
| CVE-2025-61939 | Alta (8.7) | 0.27% | — | 7 ene 2026 | An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to… |
| CVE-2018-18878 | Alta (7.5) | 2.9% | — | 18 jun 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become… |
| CVE-2018-18877 | Alta (8.8) | 1.7% | — | 18 jun 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device. |
| CVE-2018-18876 | Media (5.3) | 2.4% | — | 18 jun 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system. |
| CVE-2018-18875 | Media (5.4) | 0.93% | — | 18 jun 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script via changestationname.php. |
| CVE-2018-18880 | Media (5.4) | 0.93% | — | 18 jun 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script. |
| CVE-2018-18879 | Alta (8.8) | 2.1% | — | 18 jun 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.