CVE-2025-61939
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.4 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Vulnerability Description
An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-923
Source
NVD
Vendor
columbiaweather
Product
weather_microserver_firmware
Discussion (0)
Add Comment
No comments yet. Be the first!