CVE-2021-30004: w1.fi Hostapd

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

Affected products

  • w1.fi Hostapd: version 2.9 only
  • w1.fi Wpa Supplicant: version 2.9 only

Published 2021-04-02. Last modified 2026-07-07.