Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

W1.Fi

First CVE: Jun 21, 2012Active for: 14 yearsTotal CVEs: 50
27.1
VTI Score
Low

W1.Fi maintains the widely embedded hostapd and wpa_supplicant projects, which form the foundation of Wi-Fi Protected Access (WPA) authentication and access-point functionality across Linux-based systems, embedded devices, and network infrastructure. The vendor's vulnerability footprint, though modest in volume, is strategically significant because these components sit at the authentication boundary between wireless clients and networks, giving defects in cryptographic implementation and protocol handling outsized security impact. The recurring weakness classes center on cryptographic weaknesses—particularly insufficient randomness, nonce reuse, and key-handling errors—alongside memory-safety and authentication-logic issues that are endemic to low-level wireless security implementations. Defenders should monitor this vendor's releases closely despite the narrow product portfolio, as patches often address fundamental protocol or implementation flaws that affect every downstream deployment; current severity and exploitation data are shown alongside this summary.

FAUCET AI Generated
50
Total CVEs
More Total CVEs than 98% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by W1.Fi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 21, 2012
14 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-23303CRITICAL
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exist
Jan 17, 20229.836NONO
CVE-2022-23304CRITICAL
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue e
Jan 17, 20229.834NONO
CVE-2026-58374HIGH
In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker withi
Jun 30, 20267.132NONO
CVE-2020-12695HIGH
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment th
Jun 8, 20207.528NONO
CVE-2017-13082HIGH
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) h
Oct 17, 20178.128NONO
CVE-2019-10064HIGH
hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate u
Feb 28, 20207.526NONO
CVE-2016-10743HIGH
hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.
Mar 23, 20197.526NONO
CVE-2016-4476HIGH
hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of servi
May 9, 20167.526NONO
CVE-2024-5290HIGH
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user
Aug 7, 20247.825NONO
CVE-2021-27803HIGH
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or
Feb 26, 20217.524NONO
View all 50 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products50 CVEs
66%
24%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.0%)
Network22 (44.0%)
Unknown11 (22.0%)
Physical0 (0.0%)
Adjacent Network16 (32.0%)
Attack Complexity
Low16 (32.0%)
High23 (46.0%)
Unknown11 (22.0%)
User Interaction
None38 (76.0%)
Unknown11 (22.0%)
Required1 (2.0%)
Privileges Required
Low1 (2.0%)
High0 (0.0%)
None38 (76.0%)
Unknown11 (22.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by W1.Fi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by W1.Fi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For W1.Fi's Products

View all 6 CNAs →

Top CWEs