CVE-2026-38821
Last modified
CVE-2026-38821 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| openNDS | openNDS | < 11.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-38821?
How severe is CVE-2026-38821?
How do I fix CVE-2026-38821?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-38808SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a …5.3
- CVE-2026-3881The Performance Monitor WordPress plugin through 1.0.6 does …5.8
- CVE-2026-38812RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/ge…9.8
- CVE-2026-38819Multiple memory leaks in openNDS before 11.0.0 allow an unau…5.3
- CVE-2026-3882Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-38820openNDS before 11.0.0 is susceptible to unauthenticated OS c…8.3
- CVE-2026-38822In openNDS before 11.0.0, the client_params.sh script, invok…7.6
- CVE-2026-3883Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-38834Tenda W30E V2.0 V16.01.0.21 was found to contain a command i…7.3
- CVE-2026-38835Tenda W30E V2.0 V16.01.0.21 was found to contain a command i…9.8
- CVE-2026-3884Versions of the package spin.js before 3.0.0 are vulnerable …6.1
- CVE-2026-3885The WP Shortcodes Plugin — Shortcodes Ultimate plugin for Wo…6.4
Are you affected by CVE-2026-38821?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
