---
id: CVE-2025-61939
title: >-
  An unused function in MicroServer can start a reverse SSH connection to a
  vendor registered domain, without mutual authentication
summary: >-
  An unused function in MicroServer can start a reverse SSH connection to a
  vendor registered domain, without mutual authentication. An attacker on the
  local network with admin access to the web server, and the ability to
  manipulate DNS re…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-923
vendor: columbiaweather
product: weather_microserver_firmware
affected:
  - weather_microserver_firmware < MS_4.1_14142
patched:
  - weather_microserver_firmware MS_4.1_14142
published: '2026-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61939'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-006-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-006-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00274
epssPercentile: 0.17871
ingestedAt: '2026-09-30T22:27:27.734Z'
---

## Overview

An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device.

## Affected

- `weather_microserver_firmware < MS_4.1_14142`

## Remediation

Upgrade past the affected range:

- `weather_microserver_firmware MS_4.1_14142`
