CVE-2025-24912

h

ostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.

Configurations

Configuration 1 (hide)

cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:*

History

24 Oct 2025, 18:40

Type Values Removed Values Added
First Time W1.fi
W1.fi hostapd
CPE cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:*
References () https://jvn.jp/en/jp/JVN19358384/ - () https://jvn.jp/en/jp/JVN19358384/ - Third Party Advisory
References () https://w1.fi/cgit/hostap/commit/?id=339a334551ca911187cc870f4f97ef08e11db109 - () https://w1.fi/cgit/hostap/commit/?id=339a334551ca911187cc870f4f97ef08e11db109 - Patch
References () https://w1.fi/cgit/hostap/commit/?id=726432d7622cc0088ac353d073b59628b590ea44 - () https://w1.fi/cgit/hostap/commit/?id=726432d7622cc0088ac353d073b59628b590ea44 - Patch
References () https://w1.fi/hostapd/ - () https://w1.fi/hostapd/ - Product

12 Mar 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-12 05:15

Updated : 2025-10-24 18:40


NVD link : CVE-2025-24912

Mitre link : CVE-2025-24912

CVE.ORG link : CVE-2025-24912


JSON object : View

Products Affected
CWE
CWE-826

Premature Release of Resource During Expected Lifetime