CVE-2026-38822
Medium
Elevated severity or exploit probability.
CVSS base
7.6
HIGH
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
EPSS — probability of exploitation (30 days)
2.3%
82.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-78
Published 2026-08-28 · modified 2026-09-09
Description
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.