CVE-2026-38819

Summary

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

Affected Software

VendorProductVersion RangeStatus
openNDSopenNDS0 < 11.0.0affected

Weaknesses

  • CWE-401: CWE-401 Missing Release of Memory after Effective Lifetime

References