PT-2026-82833 · Opennds · Opennds

·

CVE-2026-38821

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

7.1

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions openNDS versions prior to 11.0.0
Description A heap-based buffer overflow occurs in the http microhttpd.c file. This allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon, resulting in a denial of service, or potentially achieve remote code execution. A heap-based buffer overflow is a condition where a program writes more data to a heap memory buffer than it can hold, potentially overwriting adjacent memory.
Recommendations Update to version 11.0.0 or later.

Exploit

Fix

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38821

Affected Products

Opennds