CVE-2025-54351 is a critical buffer overflow vulnerability affecting iperf3 versions prior to 3.19.1, specifically when the --skip-rx-copy option is utilized. This flaw, rated with a CVSS score of 10.0, allows unauthenticated remote attackers to achieve complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation, exploit code, or Metasploit/Nuclei modules available, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation. Organizations using affected iperf3 versions should upgrade to 3.19.1 immediately and consider restricting access to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.19CPE matchmatch criteria | cpe:2.3:a:es:iperf3:3.19:*:*:*:*:*:*:* | ||
>= 0, < 3.19.1CPE match | cpe:2.3:a:es:iperf3:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.