Logo
componenthostapd
Name
hostapd
Version
2.11
Type
library
Description
User space daemon for extended IEEE 802.11 management
Licenses
BSD-3-Clause
PURL
-
CPE
cpe:2.3:*:w1.fi:hostapd:2.11:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
2.10
scarthgap
2.10

Patches#


#
Title
Author
Resolve
1
RADIUS: Drop pending request only when accepting the response
Jouni Malinen <j@w1.fi>
CVE-2025-24912
2
hostapd: Fix clearing up settings for color switch
Stone Zhang <quic_stonez@quicinc.com>
3
Include base64 for hostapd CONFIG_SAE_PK builds
Jouni Malinen <j@w1.fi>
4
RADIUS: Fix pending request dropping
Jouni Malinen <quic_jouni@quicinc.com>
CVE-2025-24912

Vulnerabilities#


Name
Analysis
Description
Patched
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.