Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Columbiaweather

First CVE: Jun 18, 2019Active for: 7 yearsTotal CVEs: 8

Columbiaweather produces a narrowly scoped weather microserver and its firmware, a specialized embedded platform that appears to have gained prominence in its niche deployment context. Its vulnerability profile concentrates around application-layer and access-control weaknesses including cross-site scripting, code injection, improper input validation, improper authentication, and publicly accessible shell directories, which are characteristic of web-facing embedded systems with limited security hardening. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Columbiaweather over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2019
7 years ago
Most Recent CVE
Jan 7, 2026
201 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-18877HIGH
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of
Jun 18, 20198.826NONO
CVE-2018-18879HIGH
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not saniti
Jun 18, 20198.826NONO
CVE-2025-66620HIGH
An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited
Jan 7, 20267.224NONO
CVE-2018-18878HIGH
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attacker to send specially crafted p
Jun 18, 20197.524NONO
CVE-2018-18876MEDIUM
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating
Jun 18, 20195.320NONO
CVE-2025-61939MEDIUM
An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin acces
Jan 7, 20264.419NONO
CVE-2018-18875MEDIUM
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script
Jun 18, 20195.419NONO
CVE-2018-18880MEDIUM
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject a
Jun 18, 20195.419NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
50%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low4 (50.0%)
High2 (25.0%)
None2 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Columbiaweather.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Columbiaweather — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Columbiaweather's Products

View all 2 CNAs →

Top CWEs