Home/Product/opennds captive portal
Product

opennds captive portal

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-25763
all versions
openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.
5.5MEDIUM
CVE-2023-38323
< 10.1.3
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, all
9.8CRITICAL
CVE-2023-38319
< 10.1.3
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attac
9.8CRITICAL
CVE-2023-38318
< 10.1.3
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing
9.8CRITICAL
CVE-2023-38317
< 10.1.3
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file,
9.8CRITICAL
CVE-2023-41102
< 10.1.3
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up
7.5HIGH
CVE-2023-41101
>= 9.0.0 and < 10.1.3
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate t
9.8CRITICAL
CVE-2023-38324
< 10.1.2
An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) whe
5.3MEDIUM
CVE-2023-38322
< 10.1.2
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be trig
7.5HIGH
CVE-2023-38320
< 10.1.2
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that c
7.5HIGH
CVE-2023-38316
< 10.1.2
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers c
9.8CRITICAL
CVE-2023-38315
< 10.1.2
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference tha
7.5HIGH
CVE-2023-38314
< 10.1.2
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() t
6.5MEDIUM
CVE-2023-38313
< 10.1.2
An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggere
7.5HIGH
threatengine.sh