cbcvebase.
CVE-2025-54350
published 2025-08-03

CVE-2025-54350: In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.40%
31.9th percentile
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianiperf3< iperf3 3.12-1+deb12u2 (bookworm)iperf3 3.12-1+deb12u2 (bookworm)
esiperf3< 3.19.13.19.1
esiperf3>= 0 < 3.9-1+deb11u33.9-1+deb11u3
esiperf3>= 0 < 3.12-1+deb12u23.12-1+deb12u2
esiperf3>= 0 < 3.18-2+deb13u13.18-2+deb13u1
esiperf3>= 0 < 3.19.1-13.19.1-1
esiperf3>= 0 < 3.9-1+deb11u1ubuntu0.13.9-1+deb11u1ubuntu0.1
esiperf3>= 0 < 3.18-2ubuntu0.13.18-2ubuntu0.1
esiperf3>= 0 < 3.7-3ubuntu0.1~esm23.7-3ubuntu0.1~esm2
esiperf3>= 0 < 3.16-1ubuntu0.1~esm13.16-1ubuntu0.1~esm1
esiperf3>= 3.2 < 3.19.13.19.1
msrcazl3_iperf3_3.17.1-3_on_azure_linux_3.0
msrccbl2_iperf3_3.18-1_on_cbl_mariner_2.0
msrccbl2_iperf3_3.18-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian3.7LOW
vendor_msrc3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.