🔐 CVE Alert

CVE-2026-15141

UNKNOWN 0.0

Referer Validation Bypass in TL-WR820N Web Management Interface

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.

CWE CWE-346
Vendor tp-link systems inc.
Product tl-wr820n v2
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. tl-wr820n v2

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tl-wr820n v2 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

TP-Link Systems Inc. / TL-WR820N v2
0 < 1.15.20 Build 260611 Rel.29552n

References

NVD ↗ CVE.org ↗ EPSS Data ↗
tp-link.com: https://www.tp-link.com/kr/support/download/tl-wr820n/#Firmware tp-link.com: https://www.tp-link.com/en/support/download/tl-wr820n/#Firmware tp-link.com: https://www.tp-link.com/en/support/faq/5243/

Credits

Seong Hun Jeong (HunSec)