CVE-2026-15141 PUBLISHED

Referer Validation Bypass in TL-WR820N Web Management Interface

Assigner: TPLink
Reserved: 08.07.2026 Published: 12.08.2026 Updated: 13.08.2026

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic.

Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor TP-Link Systems Inc.
Product TL-WR820N v2
Versions Default: unaffected
  • affected from 0 to 1.15.20 Build 260611 Rel.29552n (excl.)

Credits

  • Seong Hun Jeong (HunSec) finder

References

Problem Types

  • CWE-346 Origin Validation Error CWE

Impacts

  • CAPEC-104 Cross Zone Scripting