A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 02:16
Updated : 2026-09-09 15:54
NVD link : CVE-2026-38821
Mitre link : CVE-2026-38821
CVE.ORG link : CVE-2026-38821
JSON object : View
Products Affected
No product.
CWE
CWE-122
Heap-based Buffer Overflow
