CVE-2025-61939: Columbiaweather Weather Microserver Firmware

Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.

An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device.

Affected products

  • Columbiaweather Weather Microserver Firmware: before MS_4.1_14142 (fixed in MS_4.1_14142)

Published 2026-01-07. Last modified 2026-10-07.