Skip to main content

Vendor/product archive

w1.fi / hostapd CVEs

Beta · best-effort

41 CVEs tagged to w1.fi / hostapd2 Critical, 9 High, 27 Medium, 3 Low, 0 Unrated.

CVE-2026-58374

Published Jun 30, 2026

In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker with…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-24912

Published Mar 12, 2025

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-37660

Published Feb 11, 2025

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity usin…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2020-12695

Published Jun 8, 2020

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment t…

CVSS 7.5 · High
evidence mentions
4
Buzz score
24.1

CVE-2019-10064

Published Feb 28, 2020

hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5062

Published Dec 12, 2019

An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5061

Published Dec 12, 2019

An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authen…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11555

Published Apr 26, 2019

The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where a…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9495

Published Apr 17, 2019

The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplican…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2016-10743

Published Mar 23, 2019

hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13088

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sle…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2017-13087

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Res…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2017-13086

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio ra…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2017-13084

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within rad…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2017-13082

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT)…

CVSS 8.1 · High
evidence mentions
5
Buzz score
25.9
Showing 1-25 of 41 CVEsPage 1 of 2