openshwprojects OpenBK7231T是openshwprojects个人开发者的一款智能家居控制应用。 openshwprojects OpenBK7231T存在跨站请求伪造漏洞,该漏洞源于/cfg_wifi_set端点(src/httpserver/http_fns.c)接受无CSRF令牌的普通GET请求配置更改,且当web_admin_password_enabled参数缺失时会清除设备Web管理密码,可能导致跨站请求伪造攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| openshwprojects | OpenBK7231T_App | ≤ * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| openshwprojects | OpenBK7231T_App | 0 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71274 | 8.5 HIGH | OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labels |
| CVE-2026-71275 | 5.4 MEDIUM | OpenBK7231T - Reflected XSS via OTA host Parameter |
No comments yet