CVE-2026-15141

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
12/08/2026
Last modified:
12/08/2026

Description

The web<br /> interface of the affected<br /> device relies on the HTTP referrer header as part of<br /> request validation.  Requests containing empty Referer value, or omitting<br /> the Referer header entirely, may be accepted and processed due to insufficient<br /> validation logic.<br /> <br /> <br /> <br /> <br /> <br /> Successful exploitation may allow an adjacent attacker with access to the web management<br /> interface to obtain device configuration details and other sensitive<br /> information.