← Vulnerability feed

Vulnerability record · CVE-2025-54349 · published 3 August 2025

CVE-2025-54349: Es iperf3 vulnerability

EEs · Iperf3

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

10.0 CVSS 3.1 Critical EPSS 0.40% · top 68.9% CWE-193 · CWE-193
10.0CVSS 3.1 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54349 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-54351Es iperf3 vulnerabilityIn iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).EPSS 0.41%9.8CVE-2016-4303Es iperf3 classic buffer overflow vulnerabilityThe parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (cra…EPSS 7.0%7.5CVE-2024-53580Es iperf3 null pointer dereference vulnerabilityiperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.EPSS 0.92%7.5CVE-2023-38403Es iperf3 integer overflow vulnerabilityiperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.EPSS 2.0%5.9CVE-2024-26306Es iperf3 vulnerabilityiPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operation…EPSS 1.1%5.3CVE-2025-54350Es iperf3 vulnerabilityIn iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.EPSS 0.42%5.3CVE-2023-7250Es iperf3 vulnerabilityA flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less tha…EPSS 0.93%7.8CVE-2021-3156Sudo off-by-one heap overflow allows root privilege escalationSudo before 1.9.5p2 contains an off-by-one error leading to a heap-based buffer overflow. Triggering it via 'sudoedit -s' with a command-line argumen…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2025-54349), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.