CVE-2026-71273: Openshwprojects OPENBK7231T App

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the parameter is absent from the request, an else-branch silently clears the device's web admin password to an empty string.

Affected products

Published 2026-08-05. Last modified 2026-08-26.