HIGH

CVE-2026-71274

2026-08-05 CVSS v3.1
CVSS
8.5

Description

OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup with no HTML sanitization. CHANNEL_GetLabel returns these labels unsanitized, and they are rendered via hprintf255 at 15+ locations in src/httpserver/http_fns.c with no HTML encoding.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.17%
Probability of exploitation in next 30 days
7.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE