CVE-2015-3035highunder attackCWE-22

CVE-2015-3035

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.5epss 84%
from disclosure to weapon0 days
Published on NVDApr 17
metasploitApr 8
CISA KEV+2534d
exploitation probability
84%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

In short

TP-LINK routers with vulnerable firmware allow attackers to read any file on the device by using special path commands (../) in web requests. This exposes sensitive information like configuration files and user data stored on the router.

Technical detail

Directory traversal vulnerability in multiple TP-LINK router models (Archer C5/C7/C8/C9, TL-WDR and TL-WR series) allowing unauthenticated remote attackers to access arbitrary files via path traversal sequences (../) in the PATH_INFO parameter to the login/ endpoint. Exploitation requires no authentication and directly impacts confidentiality of stored data on the device.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.