Impact
A heap‑based buffer overflow exists in openNDS’s http_microhttpd.c component before version 11.0.0. An unauthenticated attacker who can reach the captive portal network can trigger the overflow, causing the openNDS daemon to crash and resulting in a denial of service. If the overflow is exploited in a way that allows arbitrary code execution, the attacker could gain remote control of the host running the daemon.
Affected Systems
The vulnerable product is openNDS; all releases older than 11.0.0 are affected. Attackers can target any installation of these versions that is exposed to an unauthenticated captive‑portal network.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. In practice, an attacker must be on the same captive‑portal network to send the malicious request, limiting external exposure. However, when the attack succeeds, it can disrupt service availability or, if the overflow is further leveraged, provide remote code execution. The lack of authentication requirements makes the flaw straightforward to exploit for an attacker with local network access.
OpenCVE Enrichment