CVE-2025-61939
An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-923
- Published
- 2026-01-07
- Last modified
- 2026-03-12
Affected products
- Columbia Weather Systems MicroServer
Weakness type
Related vulnerabilities
- CVE-2026-87734 — An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly...
- CVE-2026-62836 — Azure SQL Managed Instance Elevation of Privilege Vulnerability
- CVE-2026-18655 — Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
- CVE-2026-23904 — Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
- CVE-2026-63226 — Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement...
- CVE-2026-8920 — Improper Restriction of Communication Channel to Intended Endpoints and External Control of File...
- CVE-2026-59841 — A improper restriction of communication channel to intended endpoints vulnerability in Fortinet...
- CVE-2026-57028 — Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker