CVE-2025-24912

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
Configurations

Configuration 1 (hide)

cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:*

History

24 Oct 2025, 18:40

Type Values Removed Values Added
CPE cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:*
First Time W1.fi hostapd
W1.fi
Summary
  • (es) hostapd no procesa correctamente los paquetes RADIUS manipulados. Cuando hostapd autentica dispositivos Wi-Fi con autenticación RADIUS, un atacante ubicado entre hostapd y el servidor RADIUS podría inyectar paquetes RADIUS manipulados y forzar el fallo de las autenticaciones RADIUS.
References () https://jvn.jp/en/jp/JVN19358384/ - () https://jvn.jp/en/jp/JVN19358384/ - Third Party Advisory
References () https://w1.fi/cgit/hostap/commit/?id=339a334551ca911187cc870f4f97ef08e11db109 - () https://w1.fi/cgit/hostap/commit/?id=339a334551ca911187cc870f4f97ef08e11db109 - Patch
References () https://w1.fi/cgit/hostap/commit/?id=726432d7622cc0088ac353d073b59628b590ea44 - () https://w1.fi/cgit/hostap/commit/?id=726432d7622cc0088ac353d073b59628b590ea44 - Patch
References () https://w1.fi/hostapd/ - () https://w1.fi/hostapd/ - Product

12 Mar 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-12 05:15

Updated : 2025-10-24 18:40


NVD link : CVE-2025-24912

Mitre link : CVE-2025-24912

CVE.ORG link : CVE-2025-24912


JSON object : View

Products Affected

w1.fi

  • hostapd
CWE
CWE-826

Premature Release of Resource During Expected Lifetime