CVE-2026-15141
Low
No strong exploitation signal.
CVSS base
5.7
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS — probability of exploitation (30 days)
0.1%
2.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-346
Published 2026-08-12 · modified 2026-09-09
CVSS breakdown
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
| Attack Vector | A | Adjacent |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | H | High |
| Integrity | N | None |
| Availability | N | None |
Timeline
- 2026-08-12 — Published (NVD)
- 2026-09-09 — Last modified (NVD)
Description
The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.