CVE-2016-4476
—CVSS 3.1
7.5 high
EPSS
3%p86
Published
()
Modified
Description
hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation.
In the news0 stories
No ingested article mentions this CVE yet.