Cross-Site Scripting Vulnerability in OpenBK7231T by OpenSHW Projects
CVE-2026-71274
8.5HIGH
What is CVE-2026-71274?
The OpenBK7231T firmware has a vulnerability where unsanitized channel labels can be set via the MQTT SetChannelLabel command. This allows an attacker with broker access to inject malicious scripts into the channel labels. When users interact with the device's web panel, these scripts execute, potentially leading to unauthorized actions or data exposure. This vulnerability highlights the importance of input sanitization and secure coding practices, particularly in web interfaces.
Affected Version(s)
OpenBK7231T_App 0
