VYPR
Vendor

OpenNDS

Products
2
CVEs
19
Across products
26
Status
Private

Products

2

Recent CVEs

19
  • CVE-2023-38323CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

  • CVE-2023-38319CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

  • CVE-2023-38318CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

  • CVE-2023-38317CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

  • CVE-2023-38321HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter…

  • CVE-2026-38820HigAug 28, 2026
    risk 0.47cvss 8.3epss

    openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

  • CVE-2026-38822HigAug 28, 2026
    risk 0.42cvss 7.6epss

    In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary…

  • CVE-2026-38821HigAug 28, 2026
    risk 0.39cvss 7.1epss

    A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.

  • CVE-2024-25763MedFeb 26, 2024
    risk 0.36cvss 5.5epss 0.00

    openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.

  • CVE-2026-38819MedAug 28, 2026
    risk 0.27cvss 5.3epss

    Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

  • CVE-2023-41102HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version…

  • CVE-2023-41101CriNov 17, 2023
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and to a heap-based buffer…

  • CVE-2023-38324MedNov 17, 2023
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the default FAS key and OpenNDS is configured as FAS. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master,…

  • CVE-2023-38322HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service…

  • CVE-2023-38320HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service…

  • CVE-2023-38316CriNov 17, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2…

  • CVE-2023-38315HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a…

  • CVE-2023-38314MedNov 17, 2023
    risk 0.00cvss 6.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggering this issue results in crashing…

  • CVE-2023-38313HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a…