7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
Affected (11)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150312 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wr741nd | Version 5 |
Configuration B
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wr841n | Version 9 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150312 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wr740n | Version 5 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150317 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Archer C5 | Version 1.20 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150310 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wr841n | Version 10 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150302 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wdr3600 | Version 1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150304 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Archer C7 | Version 2 |
Configuration H
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wr841nd | Version 10 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150302 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Archer C9 | Version 1 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150310 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wr841nd | Version 9 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150316 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Archer C8 | Version 1 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150302 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wdr4300 | Version 1 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 150302 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wdr3500 | Version 1 |
References (33)
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Broken LinkThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitNot Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitNot Applicable
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.