Back

CVE-2015-3035

HIGH CISA KEV

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

Published: Apr 22, 2015 Modified: Apr 21, 2026
CWE-22 CWE-22

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: NONE Availability Impact: NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products (13)

Vendor Product Version
tp-link tl-wr741nd_firmware * < 150312
tp-link tl-wr841n_firmware * < 150310
tp-link tl-wr740n_firmware * < 150312
tp-link archer_c5_firmware * < 150317
tp-link tl-wr841n_firmware * < 150310
tp-link tl-wdr3600_firmware * < 150302
tp-link archer_c7_firmware * < 150304
tp-link tl-wr841nd_firmware * < 150310
tp-link archer_c9_firmware * < 150302
tp-link tl-wr841nd_firmware * < 150310
tp-link archer_c8_firmware * < 150316
tp-link tl-wdr4300_firmware * < 150302
tp-link tl-wdr3500_firmware * < 150302

GitHub Security Advisory GHSA-4qv6-46qm-w9fg

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 83.77%

Top 0% most likely to be exploited

Threat Score 85.1 / 100

CISA Known Exploited

Date Added: 2022-03-25
Due Date: 2022-04-15
Required Action:

Apply updates per vendor instructions.

Data Sources

NVD CISA KEV EPSS GitHub