Executive brief
openNDS is a captive portal system that manages network access for guest users. A vulnerability in its authentication service allows an unauthenticated attacker to execute arbitrary operating system commands on the server by injecting shell commands through a web request parameter, potentially compromising the entire system.
Technical details
openNDS before version 11.0.0 contains an OS command injection vulnerability (CWE-78) in the /opennds_preauth/ endpoint's fas query parameter, caused by insufficient input validation in the libopennds.sh shell script library. The vulnerability allows an unauthenticated attacker to inject arbitrary shell commands through the fas parameter, which are then executed with the privileges of the openNDS process. The attack requires network access to the openNDS service but no authentication or user interaction. A fix was implemented in commit 8c03750 to sanitize and block malicious command injection patterns.
Affected products
- openNDS openNDS before 11.0.0
Timeline
- 2026-08-28: disclosed
- 2026: patched: Fix applied in commit 8c03750; version 11.0.0 or later contains the patch