{"id":"CVE-2026-15141","title":"The web\ninterface of the affected\ndevice relies on the HTTP referrer header as part of\nrequest validation.  Requests containing empty Referer value, or omitting\nthe Referer header entirely, may be accepted and processed due to insufficie…","summary":"The web\ninterface of the affected\ndevice relies on the HTTP referrer header as part of\nrequest validation.  Requests containing empty Referer value, or omitting\nthe Referer header entirely, may be accepted and processed due to insufficie…","severity":"medium","cvss":5.7,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-346"],"vendor":"tp-link","product":"tl-wr820n_firmware","affected":["tl-wr820n_firmware < 1.15.20"],"patched":["tl-wr820n_firmware 1.15.20"],"published":"2026-08-12","updated":"2026-09-09","sourceUpdated":"2026-09-09T02:55:52.650","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15141","references":[{"url":"https://www.tp-link.com/en/support/download/tl-wr820n/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/en/support/faq/5243/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/kr/support/download/tl-wr820n/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-13T13:11:43.168498Z"},"scores":{"nvd":5.7,"cna":5.3},"ingestedAt":"2026-09-11T10:02:46.617Z","epss":0.00119,"epssPercentile":0.01998,"slug":"CVE-2026-15141","body":"## Overview\n\nThe web\ninterface of the affected\ndevice relies on the HTTP referrer header as part of\nrequest validation.  Requests containing empty Referer value, or omitting\nthe Referer header entirely, may be accepted and processed due to insufficient\nvalidation logic.\n\n\n\n\n\nSuccessful exploitation may allow an adjacent attacker with access to the web management\ninterface to obtain device configuration details and other sensitive\ninformation.\n\n## Affected\n\n- `tl-wr820n_firmware < 1.15.20`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tl-wr820n_firmware 1.15.20`","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":31.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}