PT-2026-1859 · Unknown · Microserver

Published

2026-01-07

·

Updated

2026-01-22

·

CVE-2025-66620

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MicroServer (affected versions not specified)
Description An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited shell access, enabling persistence through reverse shells, and the ability to modify or remove data stored in the file system. The webshell allows for unlimited login attempts. Successful exploitation grants sudo rights on specific files and directories. An attacker can establish persistence through reverse shells and manipulate or delete data within the file system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-66620

Affected Products

Microserver