以下是该漏洞描述的中文翻译: openNDS 11.0.0 之前的版本中存在多个内存泄漏漏洞,允许处于 Captive Portal(强制门户)网络中的未认证攻击者在几分钟内耗尽设备的所有可用内存。 术语说明: Captive Portal (强制门户/强制网关):通常指需要登录才能访问互联网的网络环境(如酒店、机场或企业WiFi),在openNDS上下文中,指的是连接到该网络的客户端。 Unauthenticated attacker:未认证攻击者,即不需要登录凭证即可利用该漏洞。 Exhaust memory*
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-38820 | 8.3 HIGH | openNDS 11.0.0前存在Shell命令注入 |
| CVE-2026-38822 | 7.6 HIGH | openNDS 11.0.0 前客户端脚本命令注入 |
| CVE-2026-38821 | 7.1 HIGH | openNDS 11.0.0 前堆缓冲区溢出漏洞 |
No comments yet