PatchSiren cyber security CVE debrief
CVE-2025-66620 Columbia Weather Systems CVE debrief
CVE-2025-66620 is a Columbia Weather Systems MicroServer firmware issue disclosed by CISA on 2026-01-06. CISA describes an unused webshell that permits unlimited login attempts; with admin access, an attacker may obtain limited shell access, persist via reverse shells, and modify or remove files on the device.
- Vendor
- Columbia Weather Systems
- Product
- MicroServer firmware
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
Organizations operating Columbia Weather Systems MicroServer firmware, especially teams responsible for embedded or industrial/OT environments and anyone managing admin access to these devices.
Technical summary
According to the CISA CSAF advisory, the MicroServer contains an unused webshell that allows unlimited login attempts and has sudo rights on certain files and directories. The advisory says an attacker with admin access to the MicroServer can gain limited shell access, enabling persistence via reverse shells and the ability to modify or remove data stored in the filesystem. The published CVSS vector is AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, which indicates high impact but also that elevated privileges and adjacent-network conditions are part of the stated attack context.
Defensive priority
High. The impact is severe for confidentiality, integrity, and availability, and CISA published a vendor fix. The issue is not described as requiring public exploitation or being KEV-listed, but affected firmware should still be prioritized for upgrade because the downside includes persistence and filesystem tampering.
Recommended defensive actions
- Update MicroServer firmware to version MS_4.1_14142 or later, per Columbia Weather Systems guidance.
- If immediate updating is not possible, restrict and closely monitor administrative access to the MicroServer.
- Review device exposure and limit adjacent-network access paths to the firmware management interface.
- Validate filesystem integrity and look for unauthorized changes on affected systems.
- Follow CISA industrial control system recommended practices and defense-in-depth guidance for segmentation, access control, and monitoring.
Evidence notes
All statements are derived from the supplied CISA CSAF source item and the official reference links included in the corpus. The advisory revision history shows initial publication and a same-day revision that updated risk evaluation, research acknowledgment, and vendor mitigations. No exploit code or unverified exploitation details are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-66620 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-66620
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-66620 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66620
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-006-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-006-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.