{"id":"CVE-2021-30004","title":"In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.","summary":"In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-20","CWE-20"],"vendor":"w1.fi","product":"hostapd","affected":["hostapd = 2.9","wpa_supplicant = 2.9"],"published":"2021-04-02","updated":"2026-07-07","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-30004","references":[{"url":"https://security.gentoo.org/glsa/202309-16","label":"cve@mitre.org"},{"url":"https://w1.fi/cgit/hostap/commit/?id=a0541334a6394f8237a4393b7372693cd7e96f15","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202309-16","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://w1.fi/cgit/hostap/commit/?id=a0541334a6394f8237a4393b7372693cd7e96f15","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01683,"epssPercentile":0.75962,"ingestedAt":"2026-07-07T19:42:41.405Z","slug":"CVE-2021-30004","body":"## Overview\n\nIn wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.\n\n## Affected\n\n- `hostapd = 2.9`\n- `wpa_supplicant = 2.9`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}