The web
interface of the affected
device relies on the HTTP referrer header as part of
request validation. Requests containing empty Referer value, or omitting
the Referer header entirely, may be accepted and processed due to insufficient
validation logic.
Successful exploitation may allow an adjacent attacker with access to the web management
interface to obtain device configuration details and other sensitive
information.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tl-wr820n/#Firmware | Product |
| https://www.tp-link.com/en/support/faq/5243/ | Vendor Advisory |
| https://www.tp-link.com/kr/support/download/tl-wr820n/#Firmware | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-08-12 23:17
Updated : 2026-09-09 02:55
NVD link : CVE-2026-15141
Mitre link : CVE-2026-15141
CVE.ORG link : CVE-2026-15141
JSON object : View
Products Affected
tp-link
- tl-wr820n_firmware
- tl-wr820n
CWE
CWE-346
Origin Validation Error
