← Back

Opennds

opennds

Vendor: Opennds • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Opennds
1Opennds
Apr 14, 2025
Feb 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.
1Opennds
1Opennds
May 29, 2025
Jan 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS c...Show more
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.Show less
1Opennds
1Opennds
Jun 20, 2025
Jan 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
1Opennds
1Opennds
Jun 20, 2025
Jan 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS command...Show more
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.Show less
1Opennds
1Opennds
Jun 3, 2025
Jan 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary...Show more
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.Show less
1Opennds
1Opennds
Nov 21, 2024
Nov 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption o...Show more
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.Show less
1Opennds
1Opennds
Nov 21, 2024
Nov 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow...Show more
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and to a heap-based buffer overflow in versions 10.x and later. Attackers may exploit the issue to crash OpenNDS (Denial-of-Service condition) or to inject and execute arbitrary bytecode (Remote Code Execution). Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.Show less