hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might allow local users to obtain sensitive information such as credentials. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2389
$ /lpg-build/cdc/sustaining/WR43RCPL26-lx03/wrlinux-4/wrlinux/../ldat/configure --enable-board=common_pc_64 --enable-rootfs=glibc_cgl --enable-kernel=cgl --enable-test=yes --enable-prebuilt-tools=no --with-product-dir=/lpg-build/cdc/sustaining/WR43RCPL26-lx03/wrlinux-4/wrlinux $ make fs