在 openNDS 11.0.0 之前的版本中, 脚本(由 openNDS 守护进程调用,用于生成经过身份验证的客户端状态页面)存在操作系统命令注入漏洞。攻击向量是通过构造的 HTTP GET 查询参数键名实现注入。经过身份验证的强制门户(captive portal)用户可以通过在 URL 查询参数名称中嵌入分号( )来注入任意 shell 命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-38820 | 8.3 HIGH | openNDS 11.0.0前存在Shell命令注入 |
| CVE-2026-38821 | 7.1 HIGH | openNDS 11.0.0 前堆缓冲区溢出漏洞 |
| CVE-2026-38819 | 5.3 MEDIUM | openNDS 11.0.0之前存在内存泄漏漏洞 |
No comments yet