Logo
componenthostapd
Name
hostapd
Version
2.11
Type
library
Description
-
Licenses
BSD-3-Clause
PURL
-
CPE
cpe:2.3:a:w1.fi:hostapd:2.11:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
2025.02.x
2.11

Patches#


#
Title
Author
Resolve
1
RADIUS: Drop pending request only when accepting the response
Jouni Malinen <j@w1.fi>
CVE-2025-24912
2
RADIUS: Fix pending request dropping
Jouni Malinen <quic_jouni@quicinc.com>
CVE-2025-24912

Vulnerabilities#


Name
Analysis
Description
Patched
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.