OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(request, "<h3>OTA requested for %s!</h3>", tmpA) with no HTML encoding, allowing a crafted URL such as /ota_exec?host=<script>alert(1)</script> to execute JavaScript in an authenticated admin's browser when they click a malicious link.

Project Subscriptions

Vendors Products
Openshwprojects Subscribe
Openbk7231t App Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 10 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title OpenBK7231T Reflected XSS via OTA host Parameter OpenBK7231T - Reflected XSS via OTA host Parameter

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Openshwprojects
Openshwprojects openbk7231t App
Vendors & Products Openshwprojects
Openshwprojects openbk7231t App

Wed, 05 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(request, "<h3>OTA requested for %s!</h3>", tmpA) with no HTML encoding, allowing a crafted URL such as /ota_exec?host=<script>alert(1)</script> to execute JavaScript in an authenticated admin's browser when they click a malicious link.
Title OpenBK7231T Reflected XSS via OTA host Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TuranSec

Published:

Updated: 2026-08-10T11:31:41.795Z

Reserved: 2026-08-05T12:23:34.967Z

Link: CVE-2026-71275

cve-icon Vulnrichment

Updated: 2026-08-05T15:56:19.489Z

cve-icon NVD

Status : Deferred

Published: 2026-08-05T13:24:51.967

Modified: 2026-08-26T17:13:24.800

Link: CVE-2026-71275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:06:53Z

Weaknesses