CVE-2026-15141: Referer Validation Bypass in TL-WR820N Web Management Interface
The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic.
Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15141?
CVE-2026-15141 has a risk score of 33, indicating a moderate level of vulnerability severity.
How do I fix CVE-2026-15141?
To mitigate CVE-2026-15141, ensure that devices are updated with the latest firmware from TP-Link.
What type of vulnerability is CVE-2026-15141?
CVE-2026-15141 is classified as a Referer Validation Bypass vulnerability in the TL-WR820N Web Management Interface.
What potential impact does CVE-2026-15141 have?
Successful exploitation of CVE-2026-15141 may allow an adjacent attacker to send unauthorized requests through the web interface.
Which device is affected by CVE-2026-15141?
CVE-2026-15141 affects the TP-Link TL-WR820N Web Management Interface.