← Terug naar overzicht

CVE-2026-38820 affects openNDS versions before 11.0.0, exposing a critical unauthenticated OS command execution vulnerability. The flaw resides in the libopennds.sh script and is exploitable via shell command injection through the 'fas' query parameter on the /opennds_preauth/ endpoint. No authentication is required to exploit this vulnerability, making it particularly dangerous for exposed deployments. openNDS is an open-source captive portal solution commonly used in network infrastructure environments. The vulnerability has been patched in version 11.0.0, with the fix committed to the official GitHub repository. Exploitation could allow a remote attacker to execute arbitrary OS commands on the affected system. The severity is considered high due to the unauthenticated nature and potential for full system compromise.

Affected products

  • openNDS before 11.0.0

Related CVE's

  • CVE-2026-38820

Categories

  • Network Infrastructure
  • Web Technologies
  • Zero-Day Vulnerabilities