VYPR
to execute JavaScript in an authenticated admin's browser when they click a malicious link.","additionalType":"https://schema.org/SoftwareApplication","sameAs":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71275"]},"keywords":"CVE-2026-71275, Openshwprojects OpenBK7231T_App","mentions":[{"@type":"SoftwareApplication","name":"OpenBK7231T_App","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Openshwprojects"}}],"isAccessibleForFree":true},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://portal.vyprsec.ai/"},{"@type":"ListItem","position":2,"name":"CVEs","item":"https://portal.vyprsec.ai/cves"},{"@type":"ListItem","position":3,"name":"CVE-2026-71275","item":"https://portal.vyprsec.ai/cves/CVE-2026-71275"}]}]}
Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026

OpenBK7231T Reflected XSS via OTA host Parameter

CVE-2026-71275

Description

OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the host query parameter directly into an HTML response via hprintf255(request, "OTA requested for %s!", tmpA) with no HTML encoding, allowing a crafted URL such as /ota_exec?host= to execute JavaScript in an authenticated admin's browser when they click a malicious link.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.