← Back to CVE List
Vulnerability Intelligence Report
TP-Link Multiple Archer Devices Directory Traversal Vulnerability

CVE-2015-3035

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:83.77%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
tp-link tl-wr741nd_firmware all
tp-link tl-wr741nd 5
tp-link tl-wr841n_firmware all
tp-link tl-wr841n 9, 10
tp-link tl-wr740n_firmware all
tp-link tl-wr740n 5
tp-link archer_c5_firmware all
tp-link archer_c5 1.20
tp-link tl-wdr3600_firmware all
tp-link tl-wdr3600 1
tp-link archer_c7_firmware all
tp-link archer_c7 2
tp-link tl-wr841nd_firmware all
tp-link tl-wr841nd 10, 9
tp-link archer_c9_firmware all
tp-link archer_c9 1
tp-link archer_c8_firmware all
tp-link archer_c8 1
tp-link tl-wdr4300_firmware all
tp-link tl-wdr4300 1
tp-link tl-wdr3500_firmware all
tp-link tl-wdr3500 1

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
83.772%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2015-04-08T00:00:00
Published2015-04-17T18:00:00
Patch Date2015-04-10
Last Updated2025-10-21T23:56:02

LINK COPIED TO CLIPBOARD