CVE-2026-38822
Last modified
CVE-2026-38822 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| openNDS | openNDS | < 11.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-38822?
How severe is CVE-2026-38822?
How do I fix CVE-2026-38822?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-3881The Performance Monitor WordPress plugin through 1.0.6 does …5.8
- CVE-2026-38812RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/ge…9.8
- CVE-2026-38819Multiple memory leaks in openNDS before 11.0.0 allow an unau…5.3
- CVE-2026-3882Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-38820openNDS before 11.0.0 is susceptible to unauthenticated OS c…8.3
- CVE-2026-38821A heap-based buffer overflow vulnerability exists in openNDS…7.1
- CVE-2026-3883Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-38834Tenda W30E V2.0 V16.01.0.21 was found to contain a command i…7.3
- CVE-2026-38835Tenda W30E V2.0 V16.01.0.21 was found to contain a command i…9.8
- CVE-2026-3884Versions of the package spin.js before 3.0.0 are vulnerable …6.1
- CVE-2026-3885The WP Shortcodes Plugin — Shortcodes Ultimate plugin for Wo…6.4
- CVE-2026-3888Local privilege escalation in snapd on Linux allows local at…7.8
Are you affected by CVE-2026-38822?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
