MEDIUM · 5.7

CVE-2026-15141

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be acc...

Vulnerability Description

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.

CVSS Score

5.7

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Tp-LinkTl-Wr820N Firmware< 1.15.20
Tp-LinkTl-Wr820N2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-15141?

CVE-2026-15141 is a vulnerability with a CVSS score of 5.7 (MEDIUM). The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be acc...

How severe is CVE-2026-15141?

CVE-2026-15141 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-15141?

Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wr820N Firmware, Tp-Link Tl-Wr820N.