Generated remediation guidance and an executive summary. No account required.
An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device.
Cite this page
CVE-2025-61939. CVEDatabase.com. Retrieved 3 May 2026. https://cvedatabase.com/cve/CVE-2025-61939
Use CWE-923, Columbiaweather vendor hub and Weather Microserver Firmware product page to widen CVE-2025-61939 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-18877, CVE-2018-18879 and CVE-2025-66620 for nearby disclosures in the same product family.