Hi,

the configuration files for hostapd (/var/run/hostapd-phyX.conf) are readable 
for everyone. This means everyone can read the wifi passwords. If a non 
privileged user calls 'uci show wireless', he will also get all wifi passwords. 
This possible e.g. for user nobody and dnsmasq.

Is this a a security issue?

Regards,
Hartmut

_______________________________________________
openwrt-devel mailing list
openwrt-devel@lists.openwrt.org
https://lists.openwrt.org/mailman/listinfo/openwrt-devel

Reply via email to