CVE-2018-18879: Columbiaweather Weather Microserver Firmware
High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.
Affected products
- Columbiaweather Weather Microserver Firmware: version ms_2.6.9900 only
Published 2019-06-18. Last modified 2026-06-17.