CVE-2019-5061

MEDIUM

hostapd 2.6 - Denial of Service via Forged Authentication and Association Request Packets

Title source: llm
STIX 2.1

Description

An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby Aps of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0092
EPSS Percentile 55.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-287 CWE-440
Status published
Products (1)
w1.fi/hostapd 2.6
Published Dec 12, 2019
Tracked Since Feb 18, 2026