← Terug naar overzicht

CVE-2026-38822 is a high-severity OS command injection vulnerability affecting openNDS versions before 11.0.0. The vulnerability exists in the client_params.sh script, which is invoked by the openNDS daemon to serve the authenticated client status page. An authenticated captive portal user can exploit this flaw by embedding semicolons in URL query parameter names within crafted HTTP GET requests, allowing arbitrary shell command execution. The issue has been addressed in openNDS version 11.0.0. A patch commit is available on the official GitHub repository. This vulnerability poses a significant risk in environments where captive portals are deployed, such as public Wi-Fi networks, hotels, and enterprise guest networks. Successful exploitation could lead to full system compromise on the affected device.

Affected products

  • openNDS before 11.0.0

Related CVE's

  • CVE-2026-38822

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Web Technologies