What is CVE-2026-71274?
CVE-2026-71274 is a vulnerability in OpenBK7231T where channel labels received via MQTT are stored and rendered without HTML sanitization. This could allow attackers to execute Cross-Site Scripting (XSS) attacks through the web interface. Users should update firmware or implement input sanitization for channel labels.
Azərbaycanca: CVE-2026-71274 OpenBK7231T cihazında MQTT vasitəsilə qəbul edilən kanal etiketlərinin HTML təmizlənməsi aparılmadan saxlanması və göstərilməsi zəifliyidir. Bu, hücumçulara veb interfeysdə XSS hücumları həyata keçirməyə imkan verə bilər. Cihazın proqram təminatını yeniləmək və ya giriş etiketlərinin sanitizasiyasını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Through which communication protocol is CVE-2026-71274 exploited on the OpenBK7231T device?
The vulnerability originates from channel labels transmitted via the MQTT protocol. These labels are stored and rendered in the web interface without HTML sanitization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.