hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.

Source