Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-3035


Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.


Published

2015-04-22T01:59:02.553

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-22
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link tl-wr841n_\(9.0\)_firmware * Yes
Hardware tp-link tl-wr841n_\(9.0\) - No
Operating System tp-link tl-wr740n_\(5.0\)_firmware ≤ 141217 Yes
Hardware tp-link tl-wr740n_\(5.0\) - No
Operating System tp-link archer_c5_\(1.2\)_firmware ≤ 141126 Yes
Hardware tp-link archer_c5_\(1.2\) - No
Operating System tp-link tl-wr841n_\(10.0\)_firmware * Yes
Hardware tp-link tl-wr841n_\(10.0\) - No
Operating System tp-link tl-wr741nd_\(5.0\)_firmware ≤ 141217 Yes
Hardware tp-link tl-wr741nd_\(5.0\) - Yes
Operating System tp-link tl-wdr3600_\(1.0\)_firmware ≤ 141022 Yes
Hardware tp-link tl-wdr3600_\(1.0\) - No
Operating System tp-link archer_c7_\(2.0\)_firmware ≤ 141110 Yes
Hardware tp-link archer_c7_\(2.0\) - No
Operating System tp-link tl-wr841nd_\(10.0\)_firmware 150104 Yes
Hardware tp-link tl-wr841nd_\(10.0\) - No
Operating System tp-link archer_c9_\(1.0\)_firmware ≤ 150122 Yes
Hardware tp-link archer_c9_\(1.0\) - No
Operating System tp-link tl-wr841nd_\(9.0\)_firmware ≤ 150104 Yes
Hardware tp-link tl-wr841nd_\(9.0\) - No
Operating System tp-link archer_c8_\(1.0\)_firmware ≤ 141023 Yes
Hardware tp-link archer_c8_\(1.0\) - No
Operating System tp-link tl-wdr4300_\(1.0\)_firmware ≤ 141113 Yes
Hardware tp-link tl-wdr4300_\(1.0\) - No
Operating System tp-link tl-wdr3500_\(1.0\)_firmware ≤ 141113 Yes
Hardware tp-link tl-wdr3500_\(1.0\) - No

References