Description
The web
interface of the affected
device relies on the HTTP referrer header as part of
request validation.  Requests containing empty Referer value, or omitting
the Referer header entirely, may be accepted and processed due to insufficient
validation logic.





Successful exploitation may allow an adjacent attacker with access to the web management
interface to obtain device configuration details and other sensitive
information.
Published: 2026-08-12
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The web interface of the affected device relies on the HTTP referrer header to validate requests. Requests that contain an empty Referer value or omit the header entirely are incorrectly accepted and processed. This insufficient verification logic corresponds to CWE‑346 and allows an attacker who has access to the web management interface to potentially read device configuration details and other sensitive information.

Affected Systems

TP‑Link Systems Inc. TL‑WR820N v2 firmware is affected. No other vendors or product versions are listed as impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. The likely attack vector is an adjacent attacker on the same local network who can reach the device's management interface. Successful exploitation requires network access to the router and does not involve remote code execution or denial of service.

Generated by OpenCVE AI on August 13, 2026 at 01:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest version once TP‑Link releases a fixed build.
  • Restrict access to the web management interface by configuring firewall rules to allow traffic only from trusted administrative IP addresses or by disabling remote access features.
  • If management access is not required locally, disable the web interface or move the device to a separate VLAN that isolates it from the rest of the network.
  • Monitor management interface logs for unusual configuration requests or repeated attempts to probe the Referer header.

Generated by OpenCVE AI on August 13, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.
Title Referer Validation Bypass in TL-WR820N Web Management Interface
Weaknesses CWE-346
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-12T22:35:58.962Z

Reserved: 2026-07-08T17:23:13.249Z

Link: CVE-2026-15141

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T23:17:19.703

Modified: 2026-08-12T23:17:19.703

Link: CVE-2026-15141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:00:13Z

Weaknesses