Vulnerability record · CVE-2015-3035 · published 22 April 2015
CVE-2015-3035: TP-Link router directory traversal allows unauthenticated file read
Tp Link · Tl Wr741nd Firmware
A path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by placing a dot-dot sequence in the PATH_INFO of the login/ endpoint. Because the affected devices are internet-facing home and small-office routers, exposed file contents such as configuration and credential data can be pulled without any login.
Description
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is unauthenticated, remotely reachable, listed in CISA KEV with a very high EPSS score, and public exploit code exists for widely deployed internet-facing routers.
What it is
A path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by placing a dot-dot sequence in the PATH_INFO of the login/ endpoint. Because the affected devices are internet-facing home and small-office routers, exposed file contents such as configuration and credential data can be pulled without any login.
Impact
An attacker gains read access to arbitrary files on the device, which can expose stored credentials, configuration and other sensitive data. The flaw is read-only; no integrity or availability impact is described.
Attack surface
Reachable over the network through the router's HTTP web interface via a crafted PATH_INFO on login/. The CVSS vector shows no privileges and no user interaction required, so the request can be sent directly to an exposed device.
Exploitation
It is listed in CISA KEV (added 2022-03-25) and has a very high EPSS probability (0.839, ~99.7th percentile), and multiple references are tagged as public exploits, indicating active exploitation and widely available exploit code.
What to do
- Update each affected model to the fixed firmware listed by TP-Link (Archer C5 before 150317, C7 before 150304, C8 before 150316, C9 1.0, TL-WDR3500/3600/4300 before 150302, TL-WR740N/741ND 5.0 before 150312, TL-WR841N/ND 9.0 and 10.0 before 150310).
- If firmware cannot be updated, replace the device or disable remote/administrative web access from untrusted networks.
- Restrict the router management interface to the LAN only and block WAN-side access to the web UI.
- Segment or retire unsupported end-of-life units that will not receive firmware fixes.
Detection
- Monitor HTTP requests to the router web interface for dot-dot sequences in the PATH_INFO of login/ or similar traversal patterns.
- Alert on unexpected outbound or inbound access to router management ports from external addresses.
- Review router logs and network flow data for repeated file-read attempts against the web interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-3035 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "TP-Link Multiple Archer Devices Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3035 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.