P2r3 develops Bareiron, a bare-metal provisioning and management platform that operates at a foundational infrastructure layer where memory-safety issues carry elevated risk. The vendor's observed vulnerability profile centers on out-of-bounds reads, classic buffer overflows, and write-what-where conditions—memory-corruption weakness classes that reflect the low-level code execution context inherent to firmware and provisioning tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by P2r3 over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69809CRITICAL A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling arbitrary code execution via a crafted pa | Mar 16, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-69808CRITICAL An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and cause a Denial of Service (DoS) via supplyi | Mar 16, 2026 | 9.1 | 31 | NO | NO |
CVE-2025-69806HIGH p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get relative information leakage via a packet sent to the server | Feb 12, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-69807HIGH p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause a denial of service via a packet sent to the server. | Feb 12, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by P2r3.
Media articles that mention a CVE ID that affects a product developed by P2r3 — matched by CVE ID, not by vendor name.