First published: Fri Nov 17 2023(Updated: )
An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the default FAS key and OpenNDS is configured as FAS. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenNDS Captive Portal | <10.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38324 is medium with a score of 5.3.
The affected software for CVE-2023-38324 is OpenNDS Captive Portal before version 10.1.2.
Users can skip the splash page sequence in OpenNDS Captive Portal before version 10.1.2 by using the default FAS key and when OpenNDS is configured as FAS (default).
To fix CVE-2023-38324, update to OpenNDS Captive Portal version 10.1.2 or above.