Record summary

CVE-2025-24912 has a selected CVSS score of 3.7 (low).

Description

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.11 and earlieraffected

References

5