Vulnerability Description
The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wr820N Firmware | < 1.15.20 |
| Tp-Link | Tl-Wr820N | 2.0 |
Related Weaknesses (CWE)
References
- https://www.tp-link.com/en/support/download/tl-wr820n/#FirmwareProduct
- https://www.tp-link.com/en/support/faq/5243/Vendor Advisory
- https://www.tp-link.com/kr/support/download/tl-wr820n/#FirmwareProduct
FAQ
What is CVE-2026-15141?
CVE-2026-15141 is a vulnerability with a CVSS score of 5.7 (MEDIUM). The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be acc...
How severe is CVE-2026-15141?
CVE-2026-15141 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15141?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wr820N Firmware, Tp-Link Tl-Wr820N.