Description
A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
Published: 2026-08-28
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in openNDS’s http_microhttpd.c component before version 11.0.0. An unauthenticated attacker who can reach the captive portal network can trigger the overflow, causing the openNDS daemon to crash and resulting in a denial of service. If the overflow is exploited in a way that allows arbitrary code execution, the attacker could gain remote control of the host running the daemon.

Affected Systems

The vulnerable product is openNDS; all releases older than 11.0.0 are affected. Attackers can target any installation of these versions that is exposed to an unauthenticated captive‑portal network.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. In practice, an attacker must be on the same captive‑portal network to send the malicious request, limiting external exposure. However, when the attack succeeds, it can disrupt service availability or, if the overflow is further leveraged, provide remote code execution. The lack of authentication requirements makes the flaw straightforward to exploit for an attacker with local network access.

Generated by OpenCVE AI on August 28, 2026 at 06:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade openNDS to version 11.0.0 or newer to eliminate the buffer overflow
  • Apply the patch from commit 3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9 if an immediate upgrade is not possible
  • Restrict access to the captive‑portal daemon or isolate it behind a firewall to limit local network exposure

Generated by OpenCVE AI on August 28, 2026 at 06:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title OpenNDS Buffer Overflow Enables Denial of Service and Remote Code Execution

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
First Time appeared Opennds
Opennds opennds
Weaknesses CWE-122
CPEs cpe:2.3:a:opennds:opennds:*:*:*:*:*:*:*:*
Vendors & Products Opennds
Opennds opennds
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T00:10:10.769Z

Reserved: 2026-04-06T10:01:05.608Z

Link: CVE-2026-38821

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:21.490

Modified: 2026-08-28T02:16:21.490

Link: CVE-2026-38821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:45:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow