CVE-2026-38820
HIGH
NVD
CVSS Score
8.3
Severity
HIGH
Published
Aug 28, 2026
Vendor
unknown
Description
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.