PT-2026-82834 · Opennds · Opennds

CVE-2026-38822

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

7.6

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions openNDS versions prior to 11.0.0
Description The client params.sh script, which is called by the openNDS daemon to provide the authenticated client status page, contains an OS command injection flaw. An authenticated captive portal user can execute arbitrary shell commands by including semicolons within the keys of HTTP GET query parameters.
Recommendations Update to version 11.0.0 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38822

Affected Products

Opennds