CVE-2025-24912: w1.fi Hostapd

Low severity, CVSS 3.7. EPSS: 0.8% chance of exploitation in the next 30 days.

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.

Affected products

  • w1.fi Hostapd: up to and including 2.11

Published 2025-03-12. Last modified 2026-06-17.