logo

New Blast-RADIUS Attack Bypasses Popular RADIUS Authentication

ID: 56c07caf-71f2-5698-acc5-f5df69341dc5

STIX ID: report--56c07caf-71f2-5698-acc5-f5df69341dc5

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2024-07-11

Date Updated: 2026-04-19

Author: Kaaviya

...
...

Blast-RADIUS is a vulnerability and attack technique against the RADIUS protocol where an attacker performs a man-in-the-middle chosen-prefix MD5 collision to transform a legitimate Access-Reject into a forged Access-Accept by injecting a malicious Proxy-State attribute; this enables authentication bypass across numerous RADIUS deployments (PAP/CHAP/MS-CHAPv2 over UDP) affecting network devices, VPNs, Wi‑Fi/802.1X, roaming/mobile offload, and critical infrastructure. The report describes attack mechanics and recommends patching and secure RADIUS configuration as mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.