Impact
The vulnerability is a memory leak that affects the openNDS captive portal. An unauthenticated attacker on the captive portal network can repeatedly exercise a code path that leaks memory, eventually exhausting the device's available RAM. The result is a denial of service as the device is forced to either halt or restart, leading to loss of network connectivity for all users.
Affected Systems
The affected product is openNDS from the openNDS project. All releases before version 11.0.0 are vulnerable. Clients running these older builds are susceptible to the memory exhaustion attack.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the lack of an EPSS score suggests that exploitation data is not yet available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated user on the captive portal network, requiring network access to the device but no privileged credentials. Because the flaw leaks memory until the system runs out of RAM, it can be triggered within minutes on a typical embedded device, potentially impacting availability in a critical network environment.
OpenCVE Enrichment