CVE-2026-71274: CWE-79 in openshwprojects OpenBK7231T_App
OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup() with no HTML sanitization. CHANNEL_GetLabel() returns these labels unsanitized, and they are rendered via hprintf255() at 15+ locations in src/httpserver/http_fns.c with no HTML encoding. An attacker with MQTT broker access (commonly unauthenticated in real deployments) can set a channel label containing a <script> payload that executes when any user views the device's web panel.
AI Analysis
Technical Summary
OpenBK7231T_App's CHANNEL_SetLabel() function uses strdup() to store channel labels received from the MQTT SetChannelLabel command without performing any HTML sanitization. The CHANNEL_GetLabel() function returns these labels unsanitized, and they are rendered in multiple locations in the HTTP server code (src/httpserver/http_fns.c) using hprintf255() without HTML encoding. Because MQTT brokers in typical deployments are often unauthenticated, an attacker with MQTT broker access can set channel labels containing <script> payloads. These payloads execute in the context of the device's web panel when viewed by users, resulting in a stored cross-site scripting vulnerability (CWE-79).
Potential Impact
Successful exploitation allows an attacker with MQTT broker access to execute arbitrary JavaScript code in the context of the device's web interface for any user viewing the channel labels. This can lead to compromise of user sessions, theft of sensitive information, or other high-impact consequences. The CVSS 3.1 base score is 8.5, reflecting high impact on confidentiality and integrity with no impact on availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict or secure MQTT broker access to trusted users only to prevent unauthorized label injection. Avoid exposing the MQTT broker to untrusted networks. Monitor for updates from the vendor for an official fix or mitigation.
CVE-2026-71274: CWE-79 in openshwprojects OpenBK7231T_App
Description
OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup() with no HTML sanitization. CHANNEL_GetLabel() returns these labels unsanitized, and they are rendered via hprintf255() at 15+ locations in src/httpserver/http_fns.c with no HTML encoding. An attacker with MQTT broker access (commonly unauthenticated in real deployments) can set a channel label containing a <script> payload that executes when any user views the device's web panel.
CVSS v3.1
Score 8.5high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenBK7231T_App's CHANNEL_SetLabel() function uses strdup() to store channel labels received from the MQTT SetChannelLabel command without performing any HTML sanitization. The CHANNEL_GetLabel() function returns these labels unsanitized, and they are rendered in multiple locations in the HTTP server code (src/httpserver/http_fns.c) using hprintf255() without HTML encoding. Because MQTT brokers in typical deployments are often unauthenticated, an attacker with MQTT broker access can set channel labels containing <script> payloads. These payloads execute in the context of the device's web panel when viewed by users, resulting in a stored cross-site scripting vulnerability (CWE-79).
Potential Impact
Successful exploitation allows an attacker with MQTT broker access to execute arbitrary JavaScript code in the context of the device's web interface for any user viewing the channel labels. This can lead to compromise of user sessions, theft of sensitive information, or other high-impact consequences. The CVSS 3.1 base score is 8.5, reflecting high impact on confidentiality and integrity with no impact on availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict or secure MQTT broker access to trusted users only to prevent unauthorized label injection. Avoid exposing the MQTT broker to untrusted networks. Monitor for updates from the vendor for an official fix or mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-05T12:23:34.967Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7336e5bf8831d539ed9256
Added to database: 08/05/2026, 13:13:09 UTC
Last enriched: 08/05/2026, 13:30:39 UTC
Last updated: 08/05/2026, 18:47:03 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.