PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66620 Columbia Weather Systems CVE debrief

CVE-2025-66620 is a Columbia Weather Systems MicroServer firmware issue disclosed by CISA on 2026-01-06. CISA describes an unused webshell that permits unlimited login attempts; with admin access, an attacker may obtain limited shell access, persist via reverse shells, and modify or remove files on the device.

Vendor
Columbia Weather Systems
Product
MicroServer firmware
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

Organizations operating Columbia Weather Systems MicroServer firmware, especially teams responsible for embedded or industrial/OT environments and anyone managing admin access to these devices.

Technical summary

According to the CISA CSAF advisory, the MicroServer contains an unused webshell that allows unlimited login attempts and has sudo rights on certain files and directories. The advisory says an attacker with admin access to the MicroServer can gain limited shell access, enabling persistence via reverse shells and the ability to modify or remove data stored in the filesystem. The published CVSS vector is AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, which indicates high impact but also that elevated privileges and adjacent-network conditions are part of the stated attack context.

Defensive priority

High. The impact is severe for confidentiality, integrity, and availability, and CISA published a vendor fix. The issue is not described as requiring public exploitation or being KEV-listed, but affected firmware should still be prioritized for upgrade because the downside includes persistence and filesystem tampering.

Recommended defensive actions

  • Update MicroServer firmware to version MS_4.1_14142 or later, per Columbia Weather Systems guidance.
  • If immediate updating is not possible, restrict and closely monitor administrative access to the MicroServer.
  • Review device exposure and limit adjacent-network access paths to the firmware management interface.
  • Validate filesystem integrity and look for unauthorized changes on affected systems.
  • Follow CISA industrial control system recommended practices and defense-in-depth guidance for segmentation, access control, and monitoring.

Evidence notes

All statements are derived from the supplied CISA CSAF source item and the official reference links included in the corpus. The advisory revision history shows initial publication and a same-day revision that updated risk evaluation, research acknowledgment, and vendor mitigations. No exploit code or unverified exploitation details are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-66620 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-66620

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-66620 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66620

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-006-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-006-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.