VulnSea

w1.fi has 4 CVEs on record between 2021 and 2025. The median CVSS is 8.2 (high), with 2 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.2
Publish → KEV
Last 90 days
0 prev 0

Products

  • hostapd 4
4
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

w1.fi vulnerabilities

CVEs affecting w1.fi, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2022-37660Medium· 6.5
1y ago

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future boots…

Sunlitw1.fi · hostapdEPSS 0.38%via NVD
CVE-2022-23304Critical· 9.8
4y ago

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.

Midnightw1.fi · hostapdEPSS 1.9%via NVD
CVE-2022-23303Critical· 9.8PoC
4y ago

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.

Abyssalw1.fi · hostapdEPSS 3.1%via NVD
CVE-2021-30004Medium· 5.3
5y ago

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

Sunlitw1.fi · hostapdEPSS 1.7%via NVD
w1.fi vulnerabilities (CVEs) · VulnSea