Vulnerability record · CVE-2012-5687 · published 1 November 2012
CVE-2012-5687: TP-LINK TL-WR841N router path traversal in web management help URI
Tp Link · Tl Wr841n
The web-based management feature on the TP-LINK TL-WR841N router (firmware 3.13.9 build 120201 Rel.54965n and earlier) is vulnerable to directory traversal. A remote attacker can place a .. (dot dot) sequence in the PATH_INFO of the help/ URI to read arbitrary files on the device. Because this is the router's administrative interface, exposed file contents can include configuration and credential material.
Description
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.
AV:N/AC:L/Au:N/C:C/I:N/A:N
Automated analysis
high priorityUnauthenticated remote arbitrary file read on an internet-exposed router with public exploit references and very high EPSS, though no KEV listing.
What it is
The web-based management feature on the TP-LINK TL-WR841N router (firmware 3.13.9 build 120201 Rel.54965n and earlier) is vulnerable to directory traversal. A remote attacker can place a .. (dot dot) sequence in the PATH_INFO of the help/ URI to read arbitrary files on the device. Because this is the router's administrative interface, exposed file contents can include configuration and credential material.
Impact
An attacker gains read access to arbitrary files on the router, which can expose stored credentials, configuration and other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP requests to the router's web management interface, specifically the help/ URI with a crafted PATH_INFO. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Public exploit references are tagged Exploit, and EPSS is high (0.68716, 99.3rd percentile), indicating elevated likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Upgrade the TL-WR841N firmware beyond 3.13.9 build 120201 Rel.54965n, or replace the device if no fixed firmware is available.
- Disable remote/Internet-facing management and restrict the web interface to trusted LAN segments only.
- Change default administrative credentials and use strong unique passwords.
- Segment or isolate the router management interface from untrusted networks.
- Monitor vendor advisories for a patched firmware release.
Detection
- Inspect HTTP request logs for help/ URIs containing .. or encoded traversal sequences in PATH_INFO.
- Alert on requests to the router management interface from unexpected or external source addresses.
- Review router configuration and file access logs for anomalous reads of sensitive files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-5687 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-5687), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.