CVE-2023-38324: Medium severity opennds captive portal vulnerability
An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the default FAS key and OpenNDS is configured as FAS. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38324?
The severity of CVE-2023-38324 is medium with a score of 5.3.
What is the affected software for CVE-2023-38324?
The affected software for CVE-2023-38324 is OpenNDS Captive Portal before version 10.1.2.
How can users skip the splash page sequence in OpenNDS Captive Portal before version 10.1.2?
Users can skip the splash page sequence in OpenNDS Captive Portal before version 10.1.2 by using the default FAS key and when OpenNDS is configured as FAS (default).
How do I fix CVE-2023-38324?
To fix CVE-2023-38324, update to OpenNDS Captive Portal version 10.1.2 or above.