Access Control Vulnerability in Dragonfly P2P File Distribution System
CVE-2025-59350

2.7LOW

Key Information:

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-59350?

The Dragonfly P2P-based file distribution and image acceleration system has a vulnerability in its access control mechanism prior to version 2.1.0. The issue arises from simple string comparisons, which make it susceptible to timing attacks. This allows an attacker to exploit the system by character-by-character password guessing, leveraging the execution time of the comparisons. This can potentially lead to unauthorized access, making it crucial for users to upgrade to version 2.1.0 or later to mitigate this risk.

Affected Version(s)

dragonfly < 2.1.0

References

CVSS V4

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59350 : Access Control Vulnerability in Dragonfly P2P File Distribution System