Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

Project Subscriptions

Vendors Products
Tp-link Subscribe
Archer C5 Subscribe
Archer C5 Firmware Subscribe
Archer C7 Subscribe
Archer C7 Firmware Subscribe
Archer C8 Subscribe
Archer C8 Firmware Subscribe
Archer C9 Subscribe
Archer C9 Firmware Subscribe
Tl-wdr3500 Subscribe
Tl-wdr3500 Firmware Subscribe
Tl-wdr3600 Subscribe
Tl-wdr3600 Firmware Subscribe
Tl-wdr4300 Subscribe
Tl-wdr4300 Firmware Subscribe
Tl-wr740n Subscribe
Tl-wr740n Firmware Subscribe
Tl-wr741nd Subscribe
Tl-wr741nd Firmware Subscribe
Tl-wr841n Subscribe
Tl-wr841n Firmware Subscribe
Tl-wr841nd Subscribe
Tl-wr841nd Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 21 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link archer C5
Tp-link archer C5 Firmware
Tp-link archer C7
Tp-link archer C7 Firmware
Tp-link archer C8
Tp-link archer C8 Firmware
Tp-link archer C9
Tp-link archer C9 Firmware
Tp-link tl-wdr3500
Tp-link tl-wdr3500 Firmware
Tp-link tl-wdr3600
Tp-link tl-wdr3600 Firmware
Tp-link tl-wdr4300
Tp-link tl-wdr4300 Firmware
Tp-link tl-wr740n
Tp-link tl-wr740n Firmware
Tp-link tl-wr741nd
Tp-link tl-wr741nd Firmware
Tp-link tl-wr841n
Tp-link tl-wr841n Firmware
Tp-link tl-wr841nd
Tp-link tl-wr841nd Firmware
CPEs cpe:2.3:h:tp-link:archer_c5_\(1.2\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_c7_\(2.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_c8_\(1.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_c9_\(1.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr3500_\(1.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr3600_\(1.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr4300_\(1.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr740n_\(5.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr741nd_\(5.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841n_\(10.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841n_\(9.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841nd_\(10.0\):-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841nd_\(9.0\):-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_c5_\(1.2\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_c7_\(2.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_c8_\(1.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_c9_\(1.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wdr3500_\(1.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wdr3600_\(1.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wdr4300_\(1.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr740n_\(5.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr741nd_\(5.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr841n_\(10.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr841n_\(9.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr841nd_\(10.0\)_firmware:150104:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr841nd_\(9.0\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_c5:1.20:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_c7:2:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_c8:1:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_c9:1:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr3500:1:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr3600:1:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr4300:1:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr740n:5:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr741nd:5:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841n:10:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841n:9:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841nd:10:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr841nd:9:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_c5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_c7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_c8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_c9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wdr3500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wdr3600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wdr4300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr740n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr741nd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr841n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wr841nd_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tp-link archer C5 \(1.2\)
Tp-link archer C5 \(1.2\) Firmware
Tp-link archer C7 \(2.0\)
Tp-link archer C7 \(2.0\) Firmware
Tp-link archer C8 \(1.0\)
Tp-link archer C8 \(1.0\) Firmware
Tp-link archer C9 \(1.0\)
Tp-link archer C9 \(1.0\) Firmware
Tp-link tl-wdr3500 \(1.0\)
Tp-link tl-wdr3500 \(1.0\) Firmware
Tp-link tl-wdr3600 \(1.0\)
Tp-link tl-wdr3600 \(1.0\) Firmware
Tp-link tl-wdr4300 \(1.0\)
Tp-link tl-wdr4300 \(1.0\) Firmware
Tp-link tl-wr740n \(5.0\)
Tp-link tl-wr740n \(5.0\) Firmware
Tp-link tl-wr741nd \(5.0\)
Tp-link tl-wr741nd \(5.0\) Firmware
Tp-link tl-wr841n \(10.0\)
Tp-link tl-wr841n \(10.0\) Firmware
Tp-link tl-wr841n \(9.0\)
Tp-link tl-wr841n \(9.0\) Firmware
Tp-link tl-wr841nd \(10.0\)
Tp-link tl-wr841nd \(10.0\) Firmware
Tp-link tl-wr841nd \(9.0\)
Tp-link tl-wr841nd \(9.0\) Firmware
Tp-link archer C5
Tp-link archer C5 Firmware
Tp-link archer C7
Tp-link archer C7 Firmware
Tp-link archer C8
Tp-link archer C8 Firmware
Tp-link archer C9
Tp-link archer C9 Firmware
Tp-link tl-wdr3500
Tp-link tl-wdr3500 Firmware
Tp-link tl-wdr3600
Tp-link tl-wdr3600 Firmware
Tp-link tl-wdr4300
Tp-link tl-wdr4300 Firmware
Tp-link tl-wr740n
Tp-link tl-wr740n Firmware
Tp-link tl-wr741nd
Tp-link tl-wr741nd Firmware
Tp-link tl-wr841n
Tp-link tl-wr841n Firmware
Tp-link tl-wr841nd
Tp-link tl-wr841nd Firmware

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Tue, 04 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-03-25'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-21T23:56:02.932Z

Reserved: 2015-04-08T00:00:00.000Z

Link: CVE-2015-3035

cve-icon Vulnrichment

Updated: 2024-08-06T05:32:21.387Z

cve-icon NVD

Status : Analyzed

Published: 2015-04-22T01:59:02.553

Modified: 2026-04-21T17:05:04.577

Link: CVE-2015-3035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses