← Vulnerability feed

Vulnerability record · CVE-2015-3035 · published 22 April 2015

CVE-2015-3035: TP-Link router directory traversal allows unauthenticated file read

Tp Link · Tl Wr741nd Firmware

A path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by placing a dot-dot sequence in the PATH_INFO of the login/ endpoint. Because the affected devices are internet-facing home and small-office routers, exposed file contents such as configuration and credential data can be pulled without any login.

7.5 CVSS 3.1 High CISA KEV since 25 Mar 2022 EPSS 84% · top 0.3% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 7.8
84%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
11Affected product versions listed by NVD
33References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is unauthenticated, remotely reachable, listed in CISA KEV with a very high EPSS score, and public exploit code exists for widely deployed internet-facing routers.

What it is

A path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by placing a dot-dot sequence in the PATH_INFO of the login/ endpoint. Because the affected devices are internet-facing home and small-office routers, exposed file contents such as configuration and credential data can be pulled without any login.

Impact

An attacker gains read access to arbitrary files on the device, which can expose stored credentials, configuration and other sensitive data. The flaw is read-only; no integrity or availability impact is described.

Attack surface

Reachable over the network through the router's HTTP web interface via a crafted PATH_INFO on login/. The CVSS vector shows no privileges and no user interaction required, so the request can be sent directly to an exposed device.

Exploitation

It is listed in CISA KEV (added 2022-03-25) and has a very high EPSS probability (0.839, ~99.7th percentile), and multiple references are tagged as public exploits, indicating active exploitation and widely available exploit code.

What to do

  • Update each affected model to the fixed firmware listed by TP-Link (Archer C5 before 150317, C7 before 150304, C8 before 150316, C9 1.0, TL-WDR3500/3600/4300 before 150302, TL-WR740N/741ND 5.0 before 150312, TL-WR841N/ND 9.0 and 10.0 before 150310).
  • If firmware cannot be updated, replace the device or disable remote/administrative web access from untrusted networks.
  • Restrict the router management interface to the LAN only and block WAN-side access to the web UI.
  • Segment or retire unsupported end-of-life units that will not receive firmware fixes.

Detection

  • Monitor HTTP requests to the router web interface for dot-dot sequences in the PATH_INFO of login/ or similar traversal patterns.
  • Alert on unexpected outbound or inbound access to router management ports from external addresses.
  • Review router logs and network flow data for repeated file-read attempts against the web interface.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-3035 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "TP-Link Multiple Archer Devices Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/131378/TP-LINK-Local-File-Disclosure.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Apr/26 ExploitMailing ListThird Party Advisory
http://www.securityfocus.com/archive/1/535240/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/74050 Broken LinkThird Party AdvisoryVDB Entry
http://www.tp-link.com/en/download/Archer-C5_V1.20.html#Firmware Product
http://www.tp-link.com/en/download/Archer-C7_V2.html#Firmware Product
http://www.tp-link.com/en/download/Archer-C8_V1.html#Firmware Product
http://www.tp-link.com/en/download/Archer-C9_V1.html#Firmware Product
http://www.tp-link.com/en/download/TL-WDR3500_V1.html#Firmware Product
http://www.tp-link.com/en/download/TL-WDR3600_V1.html#Firmware Product
http://www.tp-link.com/en/download/TL-WDR4300_V1.html#Firmware Product
http://www.tp-link.com/en/download/TL-WR740N_V5.html#Firmware Product
http://www.tp-link.com/en/download/TL-WR741ND_V5.html#Firmware Product
http://www.tp-link.com/en/download/TL-WR841ND_V9.html#Firmware Product
http://www.tp-link.com/en/download/TL-WR841N_V9.html#Firmware Product
https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150410-0_TP-Link_Unauthenticated_local_file_dis ExploitNot Applicable
http://packetstormsecurity.com/files/131378/TP-LINK-Local-File-Disclosure.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Apr/26 ExploitMailing ListThird Party Advisory
http://www.securityfocus.com/archive/1/535240/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/74050 Broken LinkThird Party AdvisoryVDB Entry
http://www.tp-link.com/en/download/Archer-C5_V1.20.html#Firmware Product
http://www.tp-link.com/en/download/Archer-C7_V2.html#Firmware Product
http://www.tp-link.com/en/download/Archer-C8_V1.html#Firmware Product
http://www.tp-link.com/en/download/Archer-C9_V1.html#Firmware Product
http://www.tp-link.com/en/download/TL-WDR3500_V1.html#Firmware Product
http://www.tp-link.com/en/download/TL-WDR3600_V1.html#Firmware Product
http://www.tp-link.com/en/download/TL-WDR4300_V1.html#Firmware Product
http://www.tp-link.com/en/download/TL-WR740N_V5.html#Firmware Product
http://www.tp-link.com/en/download/TL-WR741ND_V5.html#Firmware Product
http://www.tp-link.com/en/download/TL-WR841ND_V9.html#Firmware Product
http://www.tp-link.com/en/download/TL-WR841N_V9.html#Firmware Product
https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150410-0_TP-Link_Unauthenticated_local_file_dis ExploitNot Applicable
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3035 US Government Resource

Track CVE-2015-3035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-9377TP-Link Archer C7 and TL-WR841N Parental Control OS Command InjectionAn OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an au…KEVEPSS 34%analysed6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed9.8CVE-2022-4498Tp-link archer c5 firmware out-of-bounds write vulnerabilityIn TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sen…EPSS 1.8%9.8CVE-2020-35575Tp-link wa901nd firmware vulnerabilityA password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web pan…EPSS 7.6%8.8CVE-2023-38563Tp-link archer c1200 firmware os command injection vulnerabilityArcher C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9(JP)_V3_230508' allow a netwo…EPSS 0.55%8.8CVE-2019-6487Tp-link tl-wdr5620 firmware os command injection vulnerabilityTP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execu…EPSS 8.5%8.0CVE-2023-39224Tp-link archer c7 firmware os command injection vulnerabilityArcher C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to…EPSS 0.40%7.5CVE-2022-4499Tp-link archer c5 firmware observable discrepancy vulnerabilityTP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials in httpd, is susceptible to a …EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2015-3035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.