CyberRota Analysis
AI-GeneratedOpenNDS versions prior to 11.0.0 are vulnerable to unauthenticated OS command execution due to a shell command injection flaw in the fas query parameter on the /opennds_preauth/ endpoint. This vulnerability could allow attackers to execute arbitrary commands on the server, potentially leading to full system compromise. Organizations using OpenNDS should prioritize patching to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.