CVE-2026-71274: Openshwprojects OPENBK7231T App
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup with no HTML sanitization. CHANNEL_GetLabel returns these labels unsanitized, and they are rendered via hprintf255 at 15+ locations in src/httpserver/http_fns.c with no HTML encoding.
Affected products
- Openshwprojects OPENBK7231T App: any version
Published 2026-08-05. Last modified 2026-08-26.