PT-2026-68146 · Unknown · Openbk7231T

·

CVE-2026-71273

·

Published

2026-08-05

·

Updated

2026-08-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenBK7231T (affected versions not specified)
Description The '/cfg wifi set' endpoint in 'src/httpserver/http fns.c' allows configuration changes through a GET request without requiring a Cross-Site Request Forgery (CSRF) token. CSRF is a type of attack that tricks a victim into submitting a malicious request. If the web admin password enabled parameter is missing from the request, the system clears the web admin password, setting it to an empty string. This allows an attacker to use a one-click payload to hijack the WiFi configuration and disable password protection if an authenticated administrator visits a malicious link.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71273

Affected Products

Openbk7231T