Cross-Site Scripting Vulnerability in OpenBK7231T by OpenSHW Projects
CVE-2026-71274

8.5HIGH

Key Information:

Vendor
CVE Published:
5 August 2026

What is CVE-2026-71274?

The OpenBK7231T firmware has a vulnerability where unsanitized channel labels can be set via the MQTT SetChannelLabel command. This allows an attacker with broker access to inject malicious scripts into the channel labels. When users interact with the device's web panel, these scripts execute, potentially leading to unauthorized actions or data exposure. This vulnerability highlights the importance of input sanitization and secure coding practices, particularly in web interfaces.

Affected Version(s)

OpenBK7231T_App 0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alibek Baxtiyorov
.