Impact
The flaw occurs in the /opennds_preauth/ endpoint where the fas query parameter is passed unsanitized to a shell script, enabling shell command injection (CWE-78). This permits an attacker, without authentication, to execute arbitrary OS commands, potentially compromising the device's operating system.
Affected Systems
The affected product is openNDS openNDS software released prior to version 11.0.0. Devices running any of these earlier releases of openNDS are susceptible to the flaw.
Risk and Exploitability
The CVSS score of 8.3 places this vulnerability in the high severity range, indicating that exploitation could threaten the system. The flaw is exposed over the network via the /opennds_preauth/ endpoint, so the likely attack vector is network-based. Based on the description, an attacker can trigger the injection from any device on the same network or, if the gateway is publicly reachable, from the internet. The EPSS score is 3%, indicating a low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the accessible attack surface and the potential impact make it a high‑risk issue.
OpenCVE Enrichment