


Perceptive Security
SOC/SIEM Consultancy

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth…
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 05:01:53
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies, Zero-Day Vulnerabilities
CVE-2026-38820 affects openNDS versions before 11.0.0, exposing a critical unauthenticated OS command execution vulnerability. The flaw resides in the libopennds.sh script and is exploitable via shell command injection through the 'fas' query parameter on the /opennds_preauth/ endpoint. No authentication is required to exploit this vulnerability, making it particularly dangerous for exposed deployments. openNDS is an open-source captive portal solution commonly used in network infrastructure environments. The vulnerability has been patched in version 11.0.0, with the fix committed to the official GitHub repository. Exploitation could allow a remote attacker to execute arbitrary OS commands on the affected system. The severity is considered high due to the unauthenticated nature and potential for full system compromise.
Technical details
Mitigation steps:
Affected products:
openNDS before 11.0.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-38820
https://github.com/openNDS/openNDS/commit/8c03750d9a17d601fa7bd03ae7cde20c7c8d1252
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
