CVE-2016-10743: w1.fi Hostapd

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.

Affected products

  • w1.fi Hostapd: before 2.6 (fixed in 2.6)

Published 2019-03-23. Last modified 2026-06-17.