CVE-2026-71274: Openshwprojects OPENBK7231T App

High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.

OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup with no HTML sanitization. CHANNEL_GetLabel returns these labels unsanitized, and they are rendered via hprintf255 at 15+ locations in src/httpserver/http_fns.c with no HTML encoding.

Affected products

Published 2026-08-05. Last modified 2026-08-26.