← Vulnerability feed

Vulnerability record · CVE-2025-54351 · published 3 August 2025

CVE-2025-54351: Es iperf3 vulnerability

EEs · Iperf3

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

10.0 CVSS 3.1 Critical EPSS 0.41% · top 67.2% CWE-420 · CWE-420
10.0CVSS 3.1 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54351 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-54349Es iperf3 vulnerabilityIn iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.EPSS 0.40%9.8CVE-2016-4303Es iperf3 classic buffer overflow vulnerabilityThe parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (cra…EPSS 7.0%7.5CVE-2024-53580Es iperf3 null pointer dereference vulnerabilityiperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.EPSS 0.92%7.5CVE-2023-38403Es iperf3 integer overflow vulnerabilityiperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.EPSS 2.0%5.9CVE-2024-26306Es iperf3 vulnerabilityiPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operation…EPSS 1.1%5.3CVE-2025-54350Es iperf3 vulnerabilityIn iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.EPSS 0.42%5.3CVE-2023-7250Es iperf3 vulnerabilityA flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less tha…EPSS 0.93%9.8CVE-2025-54309CrushFTP AS2 validation flaw grants remote admin accessCrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 mishandle AS2 validation when the DMZ proxy feature is not in use, letting remote attackers obtain …KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2025-54351), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.