---
id: CVE-2021-30004
title: >-
  In wpa_supplicant and hostapd 2.9, forging attacks may occur because
  AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
summary: >-
  In wpa_supplicant and hostapd 2.9, forging attacks may occur because
  AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-20
  - CWE-20
vendor: w1.fi
product: hostapd
affected:
  - hostapd = 2.9
  - wpa_supplicant = 2.9
published: '2021-04-02'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-30004'
references:
  - url: 'https://security.gentoo.org/glsa/202309-16'
    label: cve@mitre.org
  - url: >-
      https://w1.fi/cgit/hostap/commit/?id=a0541334a6394f8237a4393b7372693cd7e96f15
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/202309-16'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://w1.fi/cgit/hostap/commit/?id=a0541334a6394f8237a4393b7372693cd7e96f15
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01683
epssPercentile: 0.75985
ingestedAt: '2026-07-07T19:42:41.405Z'
---

## Overview

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

## Affected

- `hostapd = 2.9`
- `wpa_supplicant = 2.9`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
