WPA Supplicant is a widely embedded Wi-Fi client authentication component that handles WPA/WPA2 protocol negotiation across Linux systems, embedded devices, and mobile platforms; its compact codebase concentrates on a single core product with high downstream distribution. The recurring weakness pattern centers on memory-buffer boundary violations and related memory-safety issues inherent to the C-based implementation of cryptographic protocol handling, a common fixture in authentication and encryption software. Live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpa Supplicant over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6025HIGH Stack-based buffer overflow in driver_wext.c in wpa_supplicant 0.6.0 and earlier allows remote attackers to cause a denial of service (crash) via crafted TSF data. | Nov 19, 2007 | 7.1 | 19 | NO | NO |
CVE-2005-0470MEDIUM Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data. | Mar 14, 2005 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpa Supplicant.
Media articles that mention a CVE ID that affects a product developed by Wpa Supplicant — matched by CVE ID, not by vendor name.