Source: opennds
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security

Hi,

The following vulnerabilities were published for opennds.

CVE-2026-38819[0]:
| Multiple memory leaks in openNDS before 11.0.0 allow an
| unauthenticated attacker on the captive portal network to exhaust
| all available memory on the device within minutes.

Fixed by: 
https://github.com/openNDS/openNDS/commit/f2332e68c6d34f8403db346e380fff3817020d5c
 (v11.0.0)
Fixed by: 
https://github.com/openNDS/openNDS/commit/b2801d9f14af44a23be7e9a1c378623bc5947c4c
 (v11.0.0)


CVE-2026-38820[1]:
| openNDS before 11.0.0 is susceptible to unauthenticated OS command
| execution via shell command injection through the fas query
| parameter on the /opennds_preauth/ endpoint because of
| libopennds.sh.

Fixed by: 
https://github.com/openNDS/openNDS/commit/8c03750d9a17d601fa7bd03ae7cde20c7c8d1252
 (v11.0.0)

CVE-2026-38821[2]:
| A heap-based buffer overflow vulnerability exists in openNDS before
| 11.0.0 that allows an unauthenticated attacker on the captive portal
| network to crash the openNDS daemon (denial of service) and
| potentially achieve remote code execution. This is in
| http_microhttpd.c.

Fixed by: 
https://github.com/openNDS/openNDS/commit/3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9
 (v11.0.0)

CVE-2026-38822[3]:
| In openNDS before 11.0.0, the client_params.sh script, invoked by
| the openNDS daemon to serve the authenticated client status page, is
| vulnerable to OS command injection through crafted HTTP GET query
| parameter keys. An authenticated captive portal user can inject
| arbitrary shell commands by embedding semicolons in a URL query
| parameter name.

Fixed by: 
https://github.com/openNDS/openNDS/commit/294983e859bb678eef7db06fc9f6afab0b489d8e
 (v11.0.0)


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-38819
    https://www.cve.org/CVERecord?id=CVE-2026-38819
[1] https://security-tracker.debian.org/tracker/CVE-2026-38820
    https://www.cve.org/CVERecord?id=CVE-2026-38820
[2] https://security-tracker.debian.org/tracker/CVE-2026-38821
    https://www.cve.org/CVERecord?id=CVE-2026-38821
[3] https://security-tracker.debian.org/tracker/CVE-2026-38822
    https://www.cve.org/CVERecord?id=CVE-2026-38822

Please adjust the affected versions in the BTS as needed.

Reply via email to