CVE-2026-15141
5.3
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic.
Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | TL-WR820N v2 | 0 < 1.15.20 Build 260611 Rel.29552n | affected |
Weaknesses
- CWE-346: CWE-346 Origin Validation Error
References
- https://www.tp-link.com/kr/support/download/tl-wr820n/#Firmware
- https://www.tp-link.com/en/support/download/tl-wr820n/#Firmware
- https://www.tp-link.com/en/support/faq/5243/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.