PT-2025-6404 · Hostap+3 · Hostapd+3

Published

2022-07-19

·

Updated

2025-09-03

·

CVE-2022-37660

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions hostapd versions 2.10 and earlier
Description The issue concerns the PKEX code remaining active even after a successful PKEX association. An attacker who has successfully bootstrapped public keys with another entity using PKEX in the past can subvert a future bootstrapping by passively observing public keys, reusing the encrypting element Qi, and subtracting it from the captured message M (X = M - Qi). This results in the public ephemeral key X, which is the only element required to subvert the PKEX association.
Recommendations For hostapd versions 2.10 and earlier, as a temporary workaround, consider disabling the PKEX code until a patch is available. Restrict access to the PKEX association to minimize the risk of exploitation. Avoid reusing the encrypting element Qi in the affected PKEX association until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06675
CVE-2022-37660
DLA-4123-1
USN-7317-1

Affected Products

Debian
Linuxmint
Ubuntu
Hostapd