Impact
The vulnerability resides in the OTA execution handler of OpenBK7231T, where the host query parameter is inserted unescaped into an HTML response. The missing HTML encoding allows a crafted host string to inject script payloads, creating a reflected Cross‑Site Scripting (XSS) vector that can execute arbitrary JavaScript in the browser of an authenticated administrator who opens the malicious link.
Affected Systems
Affected systems are devices running the OpenBK7231T firmware supplied by openshwprojects under the OpenBK7231T_App product name. No specific firmware versions are listed, so all releases containing the identified http_fn_ota_exec implementation are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact, with the EPSS score currently unavailable and the vulnerability not yet listed in CISA’s KEV catalog. Exploitation requires the attacker to obtain access to an administrator session that can trigger the OTA endpoint; the attack is limited to reflected XSS and does not provide remote code execution outside of the web browser context.
OpenCVE Enrichment