Impact
The web interface of the affected device relies on the HTTP referrer header to validate requests. Requests that contain an empty Referer value or omit the header entirely are incorrectly accepted and processed. This insufficient verification logic corresponds to CWE‑346 and allows an attacker who has access to the web management interface to potentially read device configuration details and other sensitive information.
Affected Systems
TP‑Link Systems Inc. TL‑WR820N v2 firmware is affected. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. The likely attack vector is an adjacent attacker on the same local network who can reach the device's management interface. Successful exploitation requires network access to the router and does not involve remote code execution or denial of service.
OpenCVE Enrichment