weather_microserver_firmware vulnerabilities
CVEs whose affected-version data names the weather_microserver_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-66620High· 8.0An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories
An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited shell access, enabling persistence through reverse shells…
▾ Twilightcolumbiaweather · weather_microserver_firmwareEPSS 0.45%via NVD
CVE-2025-61939High· 8.8An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication
An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS re…
▾ Twilightcolumbiaweather · weather_microserver_firmwareEPSS 0.27%via NVD