CVE-2026-15141
Referer Validation Bypass in TL-WR820N Web Management Interface
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.
| CWE | CWE-346 |
| Vendor | tp-link systems inc. |
| Product | tl-wr820n v2 |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. tl-wr820n v2
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tl-wr820n v2 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TP-Link Systems Inc. / TL-WR820N v2
0 < 1.15.20 Build 260611 Rel.29552n
References
Credits
Seong Hun Jeong (HunSec)