CVE-2025-24912: w1.fi Hostapd
Low severity, CVSS 3.7. EPSS: 0.8% chance of exploitation in the next 30 days.
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
Affected products
- w1.fi Hostapd: up to and including 2.11
Published 2025-03-12. Last modified 2026-06-17.