CVE-2026-38819: Medium severity OpenNDS openNDS vulnerability
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Devices running openNDS versions before 11.0.0 are exposed if an attacker can access the captive portal network. No authentication or other privileges are required.
What is the likely operational impact?
An attacker can trigger memory leaks until the device exhausts available memory, potentially within minutes. The provided severity vector indicates an availability impact with no stated confidentiality or integrity impact.
Are default deployments affected?
The available information identifies affected versions and requires access to the captive portal network, but does not state whether a default configuration is vulnerable.
What can be done if an immediate upgrade is not possible?
The provided information does not document a workaround. Restricting untrusted access to the captive portal network may reduce exposure, but this is not stated as a vendor-provided mitigation.