See how nsd compares to other vendors in security performance
Several vulnerabilities were found in NSD. The overview of the vulnerabilities with a brief description is:
CVE-2026-18664 - severity: HIGH Wrong interpretation of ACL ranges
CVE-2026-18916 - severity: MEDIUM Remote TCP DoS by throttling the TCP receive window
CVE-2026-19401 - severity: HIGH Remote UDP DoS by sending multiple DNS Cookie options
CVE-2026-19538 - severity: HIGH Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
The patches are tested to apply/work on 4.15.0.
Best regards, -- Willem, on behalf of the NSD team.
Last updated 29 June 2026
A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.