CVE-2026-38819
- EPSS 0.18%
- Veröffentlicht 28.08.2026 02:16:21
- Zuletzt bearbeitet 09.09.2026 15:54:36
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.
CVE-2026-38820
- EPSS 1.74%
- Veröffentlicht 28.08.2026 02:16:21
- Zuletzt bearbeitet 09.09.2026 15:54:36
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
CVE-2026-38821
- EPSS 0.2%
- Veröffentlicht 28.08.2026 02:16:21
- Zuletzt bearbeitet 09.09.2026 15:54:36
A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in...
CVE-2026-38822
- EPSS 0.85%
- Veröffentlicht 28.08.2026 02:16:21
- Zuletzt bearbeitet 09.09.2026 15:54:36
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal u...
CVE-2024-25763
- EPSS 0.46%
- Veröffentlicht 26.02.2024 16:27:59
- Zuletzt bearbeitet 14.04.2025 12:57:05
openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.
CVE-2023-38319
- EPSS 1.1%
- Veröffentlicht 26.01.2024 05:15:12
- Zuletzt bearbeitet 21.11.2024 08:13:19
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
CVE-2023-38323
- EPSS 1.1%
- Veröffentlicht 26.01.2024 05:15:12
- Zuletzt bearbeitet 29.05.2025 16:15:29
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
CVE-2023-38317
- EPSS 1.1%
- Veröffentlicht 26.01.2024 05:15:11
- Zuletzt bearbeitet 03.06.2025 18:15:23
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
CVE-2023-38318
- EPSS 1.1%
- Veröffentlicht 26.01.2024 05:15:11
- Zuletzt bearbeitet 21.11.2024 08:13:19
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
CVE-2023-41101
- EPSS 1.9%
- Veröffentlicht 17.11.2023 06:15:34
- Zuletzt bearbeitet 21.11.2024 08:20:34
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, ...