Opennds · Opennds · CVE-2026-38821
**Name of the Vulnerable Software and Affected Versions**
openNDS versions prior to 11.0.0
**Description**
A heap-based buffer overflow occurs in the `http microhttpd.c` file. This allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon, resulting in a denial of service, or potentially achieve remote code execution. A heap-based buffer overflow is a condition where a program writes more data to a heap memory buffer than it can hold, potentially overwriting adjacent memory.
**Recommendations**
Update to version 11.0.0 or later.