CVE-2023-38324
Description
An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the default FAS key and OpenNDS is configured as FAS. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OpenNDS before 10.1.2 allows users to skip the splash page and directly authenticate when using the default FAS key.
Vulnerability
In OpenNDS versions before 10.1.2, a weak authentication vulnerability exists when the captive portal is configured as a FAS (Forward Authentication Service) and uses the default FAS key. The issue, tracked as CWE-1390 (Weak Authentication) [1], allows users to bypass the intended splash page sequence. Affected versions: OpenNDS before 10.1.2. The fix was included in OpenNDS 10.1.2, released on 29 July 2023 [4].
Exploitation
An attacker does not need authentication or special network position; they only need the captive portal to be using the default FAS key and OpenNDS configured as FAS. By exploiting the weak authentication mechanism, the attacker can skip the splash page and proceed directly to authentication, effectively bypassing the intended flow [1][4].
Impact
Successful exploitation allows an attacker to bypass the captive portal's splash page sequence, potentially gaining network access without proper authorization or acknowledgment of terms and conditions. This undermines the authentication and consent mechanism of the captive portal [1][4].
Mitigation
The vulnerability is fixed in OpenNDS version 10.1.2, released on 29 July 2023, and in the subsequent OpenNDS 10.1.3 version [4]. The fix is included in OpenWrt master, OpenWrt 23.05, and OpenWrt 22.03 as of 28 August 2023 (by updating to OpenNDS 10.1.3) [description]. Users should upgrade to version 10.1.2 or later, or ensure the FAS key is not set to the default value.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- OpenNDS/OpenNDSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- cwe.mitre.org/data/definitions/1390.htmlmitre
- github.com/openNDS/openNDS/blob/master/ChangeLogmitre
- github.com/openNDS/openNDS/releases/tag/v10.1.2mitre
- github.com/openwrt/routing/commit/0b19771fb2dd81e7c428759610aed583171eed80mitre
- openwrt.org/docs/guide-user/services/captive-portal/openndsmitre
- source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/mitre
- www.forescout.com/resources/sierra21-vulnerabilitiesmitre
News mentions
0No linked articles in our index yet.