5.7

CVE-2026-15141

Referer Validation Bypass in TL-WR820N Web Management Interface

The web
interface of the affected
device relies on the HTTP referrer header as part of
request validation.  Requests containing empty Referer value, or omitting
the Referer header entirely, may be accepted and processed due to insufficient
validation logic.





Successful exploitation may allow an adjacent attacker with access to the web management
interface to obtain device configuration details and other sensitive
information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Tl-wr820n Firmware Version < 1.15.20
   Tp-link ≫ Tl-wr820n Version 2.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.02
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.7 2.1 3.6
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
f23511db-6c3e-4e32-a477-6aa17d310630 5.3 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://www.tp-link.com/kr/support/download/tl-wr820n/#Firmware
Product
https://www.tp-link.com/en/support/download/tl-wr820n/#Firmware
Product
https://www.tp-link.com/en/support/faq/5243/
Vendor Advisory