CVE-2026-15141

Summary

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic.

Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.TL-WR820N v20 < 1.15.20 Build 260611 Rel.29552naffected

Weaknesses

  • CWE-346: CWE-346 Origin Validation Error

References