CVE-2018-18879: Columbiaweather Weather Microserver Firmware

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.

Affected products

Published 2019-06-18. Last modified 2026-06-17.