TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-66620

HIGH
8.0

Beschreibung

An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited shell access, enabling persistence through reverse shells, and the ability to modify or remove data stored in the file system.

CVE Details

CVSS v3.1 Bewertung8.0
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorADJACENT_NETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht1/7/2026
Zuletzt geandert1/22/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

columbiaweather:weather_microservercolumbiaweather:weather_microserver_firmware

Schwachen (CWE)

CWE-553

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.