Columbiaweather produces a narrowly scoped weather microserver and its firmware, a specialized embedded platform that appears to have gained prominence in its niche deployment context. Its vulnerability profile concentrates around application-layer and access-control weaknesses including cross-site scripting, code injection, improper input validation, improper authentication, and publicly accessible shell directories, which are characteristic of web-facing embedded systems with limited security hardening. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Columbiaweather over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18877HIGH In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of | Jun 18, 2019 | 8.8 | 26 | NO | NO |
CVE-2018-18879HIGH In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not saniti | Jun 18, 2019 | 8.8 | 26 | NO | NO |
CVE-2025-66620HIGH An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited | Jan 7, 2026 | 7.2 | 24 | NO | NO |
CVE-2018-18878HIGH In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attacker to send specially crafted p | Jun 18, 2019 | 7.5 | 24 | NO | NO |
CVE-2018-18876MEDIUM In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating | Jun 18, 2019 | 5.3 | 20 | NO | NO |
CVE-2025-61939MEDIUM An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin acces | Jan 7, 2026 | 4.4 | 19 | NO | NO |
CVE-2018-18875MEDIUM In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script | Jun 18, 2019 | 5.4 | 19 | NO | NO |
CVE-2018-18880MEDIUM In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject a | Jun 18, 2019 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Columbiaweather.
Media articles that mention a CVE ID that affects a product developed by Columbiaweather — matched by CVE ID, not by vendor name.