top of page
perceptive_background_267k.jpg

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth…

Published:

28 augustus 2026 om 00:00:00

Alert date:

28 augustus 2026 om 05:01:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Web Technologies, Zero-Day Vulnerabilities

CVE-2026-38820 affects openNDS versions before 11.0.0, exposing a critical unauthenticated OS command execution vulnerability. The flaw resides in the libopennds.sh script and is exploitable via shell command injection through the 'fas' query parameter on the /opennds_preauth/ endpoint. No authentication is required to exploit this vulnerability, making it particularly dangerous for exposed deployments. openNDS is an open-source captive portal solution commonly used in network infrastructure environments. The vulnerability has been patched in version 11.0.0, with the fix committed to the official GitHub repository. Exploitation could allow a remote attacker to execute arbitrary OS commands on the affected system. The severity is considered high due to the unauthenticated nature and potential for full system compromise.

Technical details

Mitigation steps:

Affected products:

openNDS before 11.0.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page