Search CVE reports


Toggle filters

1 – 10 of 19 results


CVE-2026-38822

Medium priority
Needs evaluation

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys....

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-38821

Medium priority
Needs evaluation

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code...

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-38820

Medium priority
Needs evaluation

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-38819

Medium priority
Needs evaluation

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-25763

Medium priority

Some fixes available 2 of 3

openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Not affected Fixed Not in release Not in release Not in release
Show less packages

CVE-2023-38323

Medium priority
Ignored

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Not affected Not in release Not in release Not in release
Show less packages

CVE-2023-38319

Medium priority
Ignored

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Not affected Not in release Not in release Not in release
Show less packages

CVE-2023-38318

Medium priority
Ignored

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Not affected Not in release Not in release Not in release
Show less packages

CVE-2023-38317

Medium priority
Ignored

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Not affected Not in release Not in release Not in release
Show less packages

CVE-2023-38321

Medium priority
Ignored

OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to...

1 affected package

opennds

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opennds Not affected Not in release Not in release Not in release
Show less packages