VYPR
Vendor

Hostap

Products
2
CVEs
8
Across products
9
Status
Private

Products

2

Recent CVEs

8
  • CVE-2022-23304CriJan 17, 2022
    risk 0.64cvss 9.8epss 0.02

    The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.

  • CVE-2022-23303CriJan 17, 2022
    risk 0.64cvss 9.8epss 0.03

    The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.

  • CVE-2019-10064HigFeb 28, 2020
    risk 0.49cvss 7.5epss 0.04

    hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.

  • CVE-2016-10743HigMar 23, 2019
    risk 0.49cvss 7.5epss 0.02

    hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.

  • CVE-2019-13377MedAug 15, 2019
    risk 0.39cvss 5.9epss 0.02

    The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information…

  • CVE-2019-11555MedApr 26, 2019
    risk 0.39cvss 5.9epss 0.03

    The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL…

  • CVE-2026-58374MedJun 30, 2026
    risk 0.35cvss 6.5epss 0.00

    In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker within wireless range to send a crafted management frame containing a malformed Multi-Link Element or…

  • CVE-2025-24912LowMar 12, 2025
    risk 0.24cvss 3.7epss 0.01

    hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.