Metrics
Affected Vendors & Products
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Thu, 23 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        W1.fi
         W1.fi hostapd  | 
|
| CPEs | cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        W1.fi
         W1.fi hostapd  | 
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Thu, 13 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        ssvc
         
  | 
    
        
        
        ssvc
         
  | 
Wed, 12 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-323 | |
| Metrics | 
        
        
        cvssV3_1
         
  | 
    
        
        ssvc
         
 
  | 
Wed, 12 Feb 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | hostapd: Public Key Exchange (PKEX) Reuse Vulnerability in hostapd | |
| Weaknesses | CWE-294 | |
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        cvssV3_1
         
 
  | 
Tue, 11 Feb 2025 22:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M - Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association. | |
| References | 
         | 
Status: PUBLISHED
Assigner: mitre
Published: 2025-02-11T00:00:00.000Z
Updated: 2025-11-03T19:27:21.731Z
Reserved: 2022-08-08T00:00:00.000Z
Link: CVE-2022-37660
Updated: 2025-11-03T19:27:21.731Z
Status : Modified
Published: 2025-02-11T23:15:08.140
Modified: 2025-11-03T20:15:55.780
Link: CVE-2022-37660
ReportizFlow