CVE-2019-25327: Mersenne Research, Inc PRIME95

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.

Affected products

Published 2026-02-12. Last modified 2026-06-17.