A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c. | |
| First Time appeared |
Opennds
Opennds opennds |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:opennds:opennds:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opennds
Opennds opennds |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-28T00:10:10.769Z
Reserved: 2026-04-06T10:01:05.608Z
Link: CVE-2026-38821
No data.
Status : Received
Published: 2026-08-28T02:16:21.490
Modified: 2026-08-28T02:16:21.490
Link: CVE-2026-38821
No data.
OpenCVE Enrichment
No data.
Weaknesses