← Vulnerability feed

Vulnerability record · CVE-2012-5687 · published 1 November 2012

CVE-2012-5687: TP-LINK TL-WR841N router path traversal in web management help URI

Tp Link · Tl Wr841n

The web-based management feature on the TP-LINK TL-WR841N router (firmware 3.13.9 build 120201 Rel.54965n and earlier) is vulnerable to directory traversal. A remote attacker can place a .. (dot dot) sequence in the PATH_INFO of the help/ URI to read arbitrary files on the device. Because this is the router's administrative interface, exposed file contents can include configuration and credential material.

7.8 CVSS 2.0 High EPSS 69% · top 0.7% CWE-22 · Path traversal
7.8CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.

AV:N/AC:L/Au:N/C:C/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote arbitrary file read on an internet-exposed router with public exploit references and very high EPSS, though no KEV listing.

What it is

The web-based management feature on the TP-LINK TL-WR841N router (firmware 3.13.9 build 120201 Rel.54965n and earlier) is vulnerable to directory traversal. A remote attacker can place a .. (dot dot) sequence in the PATH_INFO of the help/ URI to read arbitrary files on the device. Because this is the router's administrative interface, exposed file contents can include configuration and credential material.

Impact

An attacker gains read access to arbitrary files on the router, which can expose stored credentials, configuration and other sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via HTTP requests to the router's web management interface, specifically the help/ URI with a crafted PATH_INFO. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Public exploit references are tagged Exploit, and EPSS is high (0.68716, 99.3rd percentile), indicating elevated likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.

What to do

  • Upgrade the TL-WR841N firmware beyond 3.13.9 build 120201 Rel.54965n, or replace the device if no fixed firmware is available.
  • Disable remote/Internet-facing management and restrict the web interface to trusted LAN segments only.
  • Change default administrative credentials and use strong unique passwords.
  • Segment or isolate the router management interface from untrusted networks.
  • Monitor vendor advisories for a patched firmware release.

Detection

  • Inspect HTTP request logs for help/ URIs containing .. or encoded traversal sequences in PATH_INFO.
  • Alert on requests to the router management interface from unexpected or external source addresses.
  • Review router configuration and file access logs for anomalous reads of sensitive files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-5687 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-33538TP-Link router web interface command injection in WlanNetworkRpmTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection flaw in the /userRpm/WlanNetworkRpm component of the route…KEVEPSS 42%analysed8.6CVE-2025-9377TP-Link Archer C7 and TL-WR841N Parental Control OS Command InjectionAn OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an au…KEVEPSS 34%analysed7.5CVE-2015-3035TP-Link router directory traversal allows unauthenticated file readA path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by plac…KEVEPSS 84%analysed6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed9.8CVE-2022-25073Tp-link tl-wr841n firmware out-of-bounds write vulnerabilityTL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthent…EPSS 13%9.8CVE-2022-0162Tp-link tl-wr841n firmware cleartext transmission vulnerabilityThe vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in…EPSS 0.67%9.8CVE-2018-12575Tp-link tl-wr841n firmware improper authentication vulnerabilityOn TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of auth…EPSS 2.9%9.8CVE-2018-11714TP-Link router CGI session handling bypass allows unauthenticated actionsTP-Link TL-WR840N v5 and TL-WR841N v13 routers mishandle sessions on the /cgi/ path. Sending a Referer header of http://192.168.0.1/mainFrame.htm cau…EPSS 68%analysed

Source: NIST National Vulnerability Database (record CVE-2012-5687), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.