LOW 3.7 Microsoft

CVE-2025-24912

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.

Microsoft Security Update 2025-Mar: hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.

Affected Products

References

Published: 2025-03-11 · Source: Microsoft · Feed updated: 2026-08-10
This low severity vulnerability with a CVSS score of 3.7 was published on 2025-03-11 via Microsoft. Affected: cbl2 wpa_supplicant 2.10-3 on CBL Mariner 2.0, azl3 wpa_supplicant 2.10-3 on Azure Linux 3.0.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.