Access Control Vulnerability in Dragonfly P2P File Distribution System
CVE-2025-59350
2.7LOW
What is CVE-2025-59350?
The Dragonfly P2P-based file distribution and image acceleration system has a vulnerability in its access control mechanism prior to version 2.1.0. The issue arises from simple string comparisons, which make it susceptible to timing attacks. This allows an attacker to exploit the system by character-by-character password guessing, leveraging the execution time of the comparisons. This can potentially lead to unauthorized access, making it crucial for users to upgrade to version 2.1.0 or later to mitigate this risk.
Affected Version(s)
dragonfly < 2.1.0