---
id: CVE-2025-66620
title: >-
  An unused webshell in MicroServer allows unlimited login attempts, with sudo
  rights on certain files and directories
summary: >-
  An unused webshell in MicroServer allows unlimited login attempts, with sudo
  rights on certain files and directories. An attacker with admin access to
  MicroServer can gain limited shell access, enabling persistence through
  reverse shells…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-553
vendor: columbiaweather
product: weather_microserver_firmware
affected:
  - weather_microserver_firmware < MS_4.1_14142
patched:
  - weather_microserver_firmware MS_4.1_14142
published: '2026-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66620'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-006-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-006-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00454
epssPercentile: 0.37022
ingestedAt: '2026-09-30T23:29:32.557Z'
---

## Overview

An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited shell access, enabling persistence through reverse shells, and the ability to modify or remove data stored in the file system.

## Affected

- `weather_microserver_firmware < MS_4.1_14142`

## Remediation

Upgrade past the affected range:

- `weather_microserver_firmware MS_4.1_14142`
