{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-15141",
        "assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "state": "PUBLISHED",
        "assignerShortName": "TPLink",
        "dateReserved": "2026-07-08T17:23:13.249Z",
        "datePublished": "2026-08-12T22:35:58.962Z",
        "dateUpdated": "2026-08-13T13:11:50.851Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
                "shortName": "TPLink",
                "dateUpdated": "2026-08-12T22:35:58.962Z"
            },
            "title": "Referer Validation Bypass in TL-WR820N Web Management Interface",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-346",
                            "description": "CWE-346 Origin Validation Error",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-104",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-104 Cross Zone Scripting"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "TP-Link Systems Inc.",
                    "product": "TL-WR820N v2",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "1.15.20 Build 260611 Rel.29552n",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "The web\ninterface of the affected\ndevice relies on the HTTP referrer header as part of\nrequest validation.  Requests containing empty Referer value, or omitting\nthe Referer header entirely, may be accepted and processed due to insufficient\nvalidation logic.\n\n\n\n\n\nSuccessful exploitation may allow an adjacent attacker with access to the web management\ninterface to obtain device configuration details and other sensitive\ninformation.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>The web\ninterface of the affected\ndevice relies on the HTTP referrer header as part of\nrequest validation.&nbsp; Requests&nbsp;containing empty Referer value, or omitting\nthe Referer header entirely, may be accepted and processed due to insufficient\nvalidation logic.</p>\n\n<p>Successful exploitation may allow an adjacent attacker with access to the web management\ninterface to obtain device configuration details and other sensitive\ninformation.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.tp-link.com/kr/support/download/tl-wr820n/#Firmware",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/en/support/download/tl-wr820n/#Firmware",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/en/support/faq/5243/",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "ADJACENT",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "LOW",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "NONE",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "NONE",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 5.3,
                        "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Seong Hun Jeong (HunSec)",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.4"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-08-13T13:11:43.168498Z",
                                "id": "CVE-2026-15141",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-13T13:11:50.851Z"
                }
            }
        ]
    }
}