jvn.jp
https://jvn.jp/en/jp/JVN19358384 CVE-2025-24912
LOW
Record summary
CVE-2025-24912 has a selected CVSS score of 3.7 (low).
Description
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 2.11 and earlier | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-24912 w1.fi
https://w1.fi/cgit/hostap/commit?id=339a334551ca911187cc870f4f97ef08e11db109 w1.fi
https://w1.fi/cgit/hostap/commit?id=726432d7622cc0088ac353d073b59628b590ea44 w1.fi
https://w1.fi/hostapd