CVE-2026-15141
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
12/08/2026
Last modified:
12/08/2026
Description
The web<br />
interface of the affected<br />
device relies on the HTTP referrer header as part of<br />
request validation. Requests containing empty Referer value, or omitting<br />
the Referer header entirely, may be accepted and processed due to insufficient<br />
validation logic.<br />
<br />
<br />
<br />
<br />
<br />
Successful exploitation may allow an adjacent attacker with access to the web management<br />
interface to obtain device configuration details and other sensitive<br />
information.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM



