Executive brief
openNDS is a captive portal software used to manage network access and authentication on guest networks. Multiple memory leaks in versions before 11.0.0 allow unauthenticated attackers on the portal network to exhaust all available memory on the device within minutes, causing a denial of service and disruption to network access for all users.
Technical details
The vulnerability consists of multiple memory leaks in openNDS before version 11.0.0, rooted in improper memory management—specifically the reuse of strtok buffers before they are fully consumed (as evidenced by commit b2801d9) and overwrite issues during preemptive authentication (commit f2332e6). An unauthenticated attacker present on the captive portal network can trigger these leaks through normal network interactions, causing memory to be consumed without being released. The attack requires no special privileges and can exhaust available memory on the portal device within minutes, resulting in denial of service. The fixes have been integrated into version 11.0.0 and later releases.
Affected products
- openNDS openNDS before 11.0.0
Timeline
- 2026-08-28: disclosed
- 2026: patched: Fixed in version 11.0.0