CVE-2025-24912

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
Configurations

Configuration 1 (hide)

cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-12 05:15

Updated : 2025-10-24 18:40


NVD link : CVE-2025-24912

Mitre link : CVE-2025-24912

CVE.ORG link : CVE-2025-24912


JSON object : View

Products Affected

w1.fi

  • hostapd
CWE
CWE-826

Premature Release of Resource During Expected Lifetime