Source: opennds X-Debbugs-CC: [email protected] Severity: grave Tags: security
Hi, The following vulnerabilities were published for opennds. CVE-2026-38819[0]: | Multiple memory leaks in openNDS before 11.0.0 allow an | unauthenticated attacker on the captive portal network to exhaust | all available memory on the device within minutes. Fixed by: https://github.com/openNDS/openNDS/commit/f2332e68c6d34f8403db346e380fff3817020d5c (v11.0.0) Fixed by: https://github.com/openNDS/openNDS/commit/b2801d9f14af44a23be7e9a1c378623bc5947c4c (v11.0.0) CVE-2026-38820[1]: | openNDS before 11.0.0 is susceptible to unauthenticated OS command | execution via shell command injection through the fas query | parameter on the /opennds_preauth/ endpoint because of | libopennds.sh. Fixed by: https://github.com/openNDS/openNDS/commit/8c03750d9a17d601fa7bd03ae7cde20c7c8d1252 (v11.0.0) CVE-2026-38821[2]: | A heap-based buffer overflow vulnerability exists in openNDS before | 11.0.0 that allows an unauthenticated attacker on the captive portal | network to crash the openNDS daemon (denial of service) and | potentially achieve remote code execution. This is in | http_microhttpd.c. Fixed by: https://github.com/openNDS/openNDS/commit/3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9 (v11.0.0) CVE-2026-38822[3]: | In openNDS before 11.0.0, the client_params.sh script, invoked by | the openNDS daemon to serve the authenticated client status page, is | vulnerable to OS command injection through crafted HTTP GET query | parameter keys. An authenticated captive portal user can inject | arbitrary shell commands by embedding semicolons in a URL query | parameter name. Fixed by: https://github.com/openNDS/openNDS/commit/294983e859bb678eef7db06fc9f6afab0b489d8e (v11.0.0) If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-38819 https://www.cve.org/CVERecord?id=CVE-2026-38819 [1] https://security-tracker.debian.org/tracker/CVE-2026-38820 https://www.cve.org/CVERecord?id=CVE-2026-38820 [2] https://security-tracker.debian.org/tracker/CVE-2026-38821 https://www.cve.org/CVERecord?id=CVE-2026-38821 [3] https://security-tracker.debian.org/tracker/CVE-2026-38822 https://www.cve.org/CVERecord?id=CVE-2026-38822 Please adjust the affected versions in the BTS as needed.

