PT-2026-1845 · Columbia Weather Systems · Microserver

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2025-64305

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Columbia Weather Systems MicroServer (affected versions not specified)
Description The MicroServer copies portions of the system firmware to an unencrypted external SD card during boot. This firmware includes user and vendor secrets in plaintext. An attacker could leverage these exposed secrets to alter the vendor firmware or obtain administrative access to the web portal.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-64305

Affected Products

Microserver