CVE-2025-24912 describes a vulnerability in w1.fi hostapd where crafted RADIUS packets can disrupt Wi-Fi authentication. An attacker positioned between hostapd and the RADIUS server can inject these packets, causing authentication failures. This vulnerability has a low CVSS score of 3.7, indicating a low impact of denial of service with high attack complexity, and there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.11CPE matchmatch criteria | cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
hostapd: RADIUS Packet Processing Flaw in hostapd
Mar 12, 2025hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
Mar 11, 2025