VYPR

MicroServer

by MicroServer

CVEs (4)

  • CVE-2023-51771CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.

  • CVE-2025-61939HigJan 7, 2026
    risk 0.57cvss 8.8epss 0.00

    An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection…

  • CVE-2025-66620HigJan 7, 2026
    risk 0.52cvss 8.0epss 0.00

    An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited shell access, enabling persistence through reverse shells, and the ability to modify or remove data…

  • CVE-2025-64305MedJan 7, 2026
    risk 0.42cvss 6.5epss 0.00

    MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.