Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

Project Subscriptions

Vendors Products
Tp-link Subscribe
Archer C5 \(1.2\) Subscribe
Archer C5 \(1.2\) Firmware Subscribe
Archer C7 \(2.0\) Subscribe
Archer C7 \(2.0\) Firmware Subscribe
Archer C8 \(1.0\) Subscribe
Archer C8 \(1.0\) Firmware Subscribe
Archer C9 \(1.0\) Subscribe
Archer C9 \(1.0\) Firmware Subscribe
Tl-wdr3500 \(1.0\) Subscribe
Tl-wdr3500 \(1.0\) Firmware Subscribe
Tl-wdr3600 \(1.0\) Subscribe
Tl-wdr3600 \(1.0\) Firmware Subscribe
Tl-wdr4300 \(1.0\) Subscribe
Tl-wdr4300 \(1.0\) Firmware Subscribe
Tl-wr740n \(5.0\) Subscribe
Tl-wr740n \(5.0\) Firmware Subscribe
Tl-wr741nd \(5.0\) Subscribe
Tl-wr741nd \(5.0\) Firmware Subscribe
Tl-wr841n \(10.0\) Subscribe
Tl-wr841n \(10.0\) Firmware Subscribe
Tl-wr841n \(9.0\) Subscribe
Tl-wr841n \(9.0\) Firmware Subscribe
Tl-wr841nd \(10.0\) Subscribe
Tl-wr841nd \(10.0\) Firmware Subscribe
Tl-wr841nd \(9.0\) Subscribe
Tl-wr841nd \(9.0\) Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Tue, 04 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-03-25'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-21T23:56:02.932Z

Reserved: 2015-04-08T00:00:00.000Z

Link: CVE-2015-3035

cve-icon Vulnrichment

Updated: 2024-08-06T05:32:21.387Z

cve-icon NVD

Status : Deferred

Published: 2015-04-22T01:59:02.553

Modified: 2025-10-22T00:15:42.857

Link: CVE-2015-3035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses