CVE 7.1 HIGH

Columbia Weather Systems MicroServer Cleartext Storage in a File or on Disk_CVE-2025-64305

7.1 / 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.

Basic Information

ID CVE-2025-64305
Source icscert
Published Jan 7, 2026 at 20:02
Modified Jan 7, 2026 at 20:18

Affected Product

Vendor Columbia Weather Systems
Product MicroServer
Affected Versions Columbia Weather Systems MicroServer 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.