High severity7.5NVD Advisory· Published May 9, 2016· Updated May 6, 2026
CVE-2016-4476
CVE-2016-4476
Description
hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.openwall.com/lists/oss-security/2016/05/03/12nvdMailing ListThird Party Advisory
- www.ubuntu.com/usn/USN-3455-1nvdThird Party Advisory
News mentions
0No linked articles in our index yet.