What is CVE-2026-71275?
CVE-2026-71275 is a Reflected XSS vulnerability in the http_fn_ota_exec() function of OpenBK7231T. The `host` query parameter is directly reflected into the HTML response without sanitization, allowing execution of arbitrary JavaScript via a crafted URL. Updating the device firmware to the patched version is strongly recommended.
Azərbaycanca: CVE-2026-71275 OpenBK7231T cihazının http_fn_ota_exec() funksiyasında aşkar edilmiş Reflected XSS zəifliyidir. `host` sorğu parametri HTML kodlaması olmadan birbaşa cavaba daxil edildiyi üçün uzaqdan hücumçu xüsusi hazırlanmış URL vasitəsilə istifadəçi brauzerində JavaScript icra edə bilər. Təsirə məruz qalmamaq üçün cihaz proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which function of the OpenBK7231T device was CVE-2026-71275 discovered?
The vulnerability was discovered in the device's http_fn_ota_exec() function.
What is the recommended mitigation for the CVE-2026-71275 Reflected XSS vulnerability?
Updating the device firmware to the patched version is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.