Low severity3.7NVD Advisory· Published Mar 12, 2025· Updated Jun 17, 2026
CVE-2025-24912
CVE-2025-24912
Description
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- osv-coords12 versionspkg:deb/ubuntu/wpa@2.1-0ubuntu1.7+esm5?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/wpa@2:2.10-21ubuntu0.2?arch=source&distro=noblepkg:deb/ubuntu/wpa@2:2.10-22ubuntu0.1?arch=source&distro=oracularpkg:deb/ubuntu/wpa@2:2.10-6ubuntu2.2?arch=source&distro=jammypkg:deb/ubuntu/wpa@2:2.6-15ubuntu2.8+esm1?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/wpa@2:2.9-1ubuntu4.6?arch=source&distro=focalpkg:deb/ubuntu/wpa@2.4-0ubuntu6.8+esm1?arch=source&distro=esm-infra/xenialpkg:rpm/opensuse/hostapd&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/hostapd&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/wpa_supplicant&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/wpa_supplicant&distro=openSUSE%20Tumbleweedpkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6
>= 0+ 11 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 2.11-bp160.2.1
- (no CPE)range: < 2.11-2.1
- (no CPE)range: < 2.10-150600.7.6.1
- (no CPE)range: < 2.11-4.1
- (no CPE)range: < 2.10-150600.7.6.1
- Jouni Malinen/hostapdv5Range: 2.11 and earlier
Patches
Vulnerability mechanics
References
4- w1.fi/cgit/hostap/commit/nvdPatch
- w1.fi/cgit/hostap/commit/nvdPatch
- jvn.jp/en/jp/JVN19358384/nvdThird Party Advisory
- w1.fi/hostapd/nvdProduct
News mentions
0No linked articles in our index yet.