Vulnerabilidades em openNDS
4 resultadosAnálise Vexday
O openNDS apresenta 4 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com predominância de injeção de comando (CWE-78). Nenhuma vulnerabilidade está sob exploração ativa confirmada (KEV) e não há casos críticos registrados, o que reduz o risco imediato, mas o ciclo recente de divulgações indica um padrão de descobertas que demanda monitoramento contínuo.
CVE-2026-38820HIGHopenNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on EPSS 1.7%CVE-2026-38822HIGHIn openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulneEPSS 0.8%CVE-2026-38821HIGHA heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal netEPSS 0.2%CVE-2026-38819MEDIUMMultiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memoEPSS 0.2%