CVE-2019-25327: Mersenne Research, Inc PRIME95
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.
Affected products
- Mersenne Research, Inc PRIME95: version 29.8 only
Published 2026-02-12. Last modified 2026-06-17.