LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-38821

Published
CVSS7.1
Severityhigh
WeaknessCWE-122
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-38821

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-38821.