Impact
The client_params.sh script used by the openNDS daemon to display the authenticated client status page fails to validate query parameter names passed via HTTP GET requests. As a result, an attacker controlling a captive portal user account can inject arbitrary shell commands by inserting semicolons into the parameter key of the URL. The injected commands execute with the privileges of the openNDS process, allowing attackers to read, modify, or delete files, or alter system configuration, constituting a remote code execution vulnerability.
Affected Systems
The flaw exists in openNDS versions prior to 11.0.0. Any installation of the openNDS daemon that renders the client status page, such as deployments on routers or access points running openNDS openNDS, is potentially affected. The identified product is openNDS from the openNDS project, last known affected revision before 11.0.0. No specific sub-product or minor version is mentioned beyond the major 11.0.0 boundary.
Risk and Exploitability
The CVSS score of 7.6 classifies this flaw as high severity, and the lack of an EPSS entry indicates no current exploitation data is available. It is not listed in the CISA KEV catalog. Because the vulnerability requires an authenticated captive portal user, the attack surface is limited to legitimate users of the captive portal, but once authenticated, an attacker can execute arbitrary commands on the host system. The lack of a publicly disclosed exploit and the requirement for user authentication reduce the likelihood of widespread exploitation, yet the potential impact is significant.
OpenCVE Enrichment