MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.
Advisories

No advisories yet.

Fixes

Solution

Columbia Weather Systems recommends users update the MicroServer firmware to version MS_4.1_14142 or later. To obtain the update, users should contact Columbia Weather Systems Support directly via email (support@columbiaweather.com) or phone (503-629-0887) for assistance.


Workaround

No workaround given by the vendor.

History

Wed, 07 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Description MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.
Title Columbia Weather Systems MicroServer Cleartext Storage in a File or on Disk
Weaknesses CWE-313
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-01-07T20:18:51.054Z

Reserved: 2025-12-08T19:17:55.931Z

Link: CVE-2025-64305

cve-icon Vulnrichment

Updated: 2026-01-07T20:18:42.522Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-07T21:15:58.980

Modified: 2026-01-08T18:08:54.147

Link: CVE-2025-64305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses