Executive brief
A directory traversal vulnerability in multiple TP-Link Archer and TL-series routers allows remote unauthenticated attackers to read arbitrary files. The flaw exists due to improper handling of dot-dot (..) sequences in the PATH_INFO parameter sent to the login/ endpoint.
Affected products
- TP-LINK Archer C5 (1.2) firmware before 150317
- TP-LINK Archer C7 (2.0) firmware before 150304
- TP-LINK Archer C8 (1.0) firmware before 150316
- TP-LINK Archer C9 (1.0) firmware before 150302
- TP-LINK TL-WDR3500 (1.0) firmware before 150302
- TP-LINK TL-WDR3600 (1.0) firmware before 150302
- TP-LINK TL-WDR4300 (1.0) firmware before 150302
- TP-LINK TL-WR740N (5.0) firmware before 150312
- TP-LINK TL-WR741ND (5.0) firmware before 150312
- TP-LINK TL-WR841N (9.0/10.0) firmware before 150310
- TP-LINK TL-WR841ND (9.0/10.0) firmware before 150310
Timeline
- 2015-04-10: disclosed: Original advisory by SEC Consult
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog