Low severity3.7NVD Advisory· Published Mar 12, 2025· Updated Jun 17, 2026
CVE-2025-24912
CVE-2025-24912
Description
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- osv-coords12 versionspkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/xenialpkg:deb/ubuntu/wpa@2:2.10-6ubuntu2.2?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+esm5?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/wpa@2:2.10-22ubuntu0.1?arch=source&distro=oracularpkg:rpm/opensuse/hostapd&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/hostapd&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/wpa_supplicant&distro=openSUSE%20Tumbleweedpkg:deb/ubuntu/wpa@2:2.6-15ubuntu2.8+esm1?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/wpa@2:2.9-1ubuntu4.6?arch=source&distro=focalpkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:deb/ubuntu/wpa@2:2.10-21ubuntu0.2?arch=source&distro=noblepkg:rpm/opensuse/wpa_supplicant&distro=openSUSE%20Leap%2015.6
>= 0+ 11 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 2.11-2.1
- (no CPE)range: < 2.11-bp160.2.1
- (no CPE)range: < 2.11-4.1
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 2.10-150600.7.6.1
- (no CPE)range: >= 0
- (no CPE)range: < 2.10-150600.7.6.1
- Jouni Malinen/hostapdv5Range: 2.11 and earlier
Patches
Vulnerability mechanics
References
4- w1.fi/cgit/hostap/commit/nvdPatch
- w1.fi/cgit/hostap/commit/nvdPatch
- jvn.jp/en/jp/JVN19358384/nvdThird Party Advisory
- w1.fi/hostapd/nvdProduct
News mentions
0No linked articles in our index yet.