CVE-2026-38820: OS Command Injection
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /openndspreauth/ endpoint because of libopennds.sh.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
openNDS versions before 11.0.0 are affected. The exposed functionality is the /opennds_preauth/ endpoint.
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction. They need network access to the affected service and can inject shell commands through the fas query parameter.
What is the impact of successful exploitation?
Successful exploitation can result in OS command execution. The reported severity vector indicates high confidentiality and integrity impact and low availability impact.
What should be done if patching cannot happen immediately?
The provided information identifies the vulnerable endpoint and fas query parameter, but does not provide a documented workaround. Restricting network access to the affected service can reduce exposure until upgrading to 11.0.0 or later.