CVE-2026-38820: Opennds

High severity, CVSS 8.3. EPSS: 2.9% chance of exploitation in the next 30 days.

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

Affected products

  • Opennds Opennds: before 11.0.0 (fixed in 11.0.0)

Published 2026-08-28. Last modified 2026-09-09.