Junglewise Threat Intelligence

CVE-2026-38822: openNDS command injection in client_params.sh

CVE-2026-38822 · Severity: high · CVSS 7.6 · Published 2026-08-28

Technologies: openNDS. Vendors: openNDS.

Executive brief

openNDS is a network access control system that manages captive portal authentication for guest WiFi and hotspot networks. A vulnerability in the client status page script allows authenticated users to inject and execute arbitrary operating system commands by crafting malicious URLs, potentially compromising server integrity and enabling lateral movement within the network.

Technical details

The vulnerability is an OS command injection flaw in the client_params.sh script, which processes HTTP GET query parameters from authenticated captive portal users. The script fails to properly sanitize query parameter names, allowing attackers to inject shell metacharacters (such as semicolons) to break out of intended command context and execute arbitrary commands with the privileges of the openNDS daemon. Attack requires prior authentication to the captive portal, but no additional user interaction is needed once authenticated. The vulnerability affects openNDS before version 11.0.0 and is addressed in commit 294983e.

Affected products

  • openNDS openNDS before 11.0.0

Timeline

  • 2026-08-28: disclosed
  • 2026: patched: Fix available in version 11.0.0 and commit 294983e

References

Related threats