CVE-2023-38324: Opennds Captive Portal
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the default FAS key and OpenNDS is configured as FAS. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.
Affected products
- Opennds Captive Portal: before 10.1.2 (fixed in 10.1.2)
Published 2023-11-17. Last modified 2026-06-17.