A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OpenNDS Buffer Overflow Enables Denial of Service and Remote Code Execution |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c. | |
| First Time appeared |
Opennds
Opennds opennds |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:opennds:opennds:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opennds
Opennds opennds |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-28T00:10:10.769Z
Updated: 2026-08-28T15:24:14.987Z
Reserved: 2026-04-06T10:01:05.608Z
Link: CVE-2026-38821
Updated: 2026-08-28T15:24:08.603Z
Status : Received
Published: 2026-08-28T02:16:21.490
Modified: 2026-08-28T20:17:28.440
Link: CVE-2026-38821
No data.