threat
engine
.sh
Back
·
··:··
Home
/
Product
/
columbiaweather weather microserver firmware
Product
columbiaweather weather microserver firmware
8 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-66620
< MS_4.1_14142
An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker
8.0
HIGH
CVE-2025-61939
< MS_4.1_14142
An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication.
8.8
HIGH
CVE-2018-18878
all versions
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could a
7.5
HIGH
CVE-2018-18877
all versions
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration
8.8
HIGH
CVE-2018-18876
all versions
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to
5.3
MEDIUM
CVE-2018-18875
all versions
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote a
5.4
MEDIUM
CVE-2018-18880
all versions
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerabi
5.4
MEDIUM
CVE-2018-18879
all versions
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the under
8.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin