# CVE-2025-64305

## Summary

- **CVE ID:** CVE-2025-64305
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-313
- **Published:** Jan 7, 2026
- **Last Modified:** Mar 12, 2026

## Description

MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.

## Affected Products

- Columbia Weather Systems — MicroServer (0)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-006-01)
- [CNA](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-006-01.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._