CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM
to execute Java","url":"https://www.csirts.com/cve/CVE-2026-71275","datePublished":"2026-08-05T13:24:51.967+00:00","about":{"@type":"Thing","name":"CVE-2026-71275"},"publisher":{"@type":"Organization","name":"CSIRTS.com","url":"https://www.csirts.com"}}

CVE-2026-71275

mediumCVSS 5.4covered by 1 sourcefirst seen 2026-08-05
OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the host query parameter directly into an HTML response via hprintf255(request, "<h3>OTA requested for %s!</h3>", tmpA) with no HTML encoding, allowing a crafted URL such as /ota_exec?host=<script>alert(1)</script> to execute JavaScript in an authenticated admin's browser when they click a malicious link.

⚡ Watch CVE-2026-71275

Get an email if CVE-2026-71275 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-71275

CVE.org record

Embed the live status

CVE-2026-71275 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-71275 status](https://www.csirts.com/badge/CVE-2026-71275)](https://www.csirts.com/cve/CVE-2026-71275)