CVE-2015-3035: TP-Link Multiple Archer Devices Directory Traversal Vulnerability

Published Apr 17, 2015
·
Updated

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATHINFO to login/.

Other sources

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATHINFO to login/.

CISA

Affected Software

53 affected components
TP-Link Multiple Archer Devices
TP-Link Tl-wr841n \(9.0\) Firmware
TP-Link Tl-wr841n \(9.0\)
TP-Link Tl-wr740n \(5.0\) Firmware<=141217
TP-Link Tl-wr740n \(5.0\)
TP-Link Archer C5 \(1.2\) Firmware<=141126
TP-Link Archer C5 \(1.2\)
TP-Link Tl-wr841n \(10.0\) Firmware
TP-Link Tl-wr841n \(10.0\)
TP-Link Tl-wr741nd \(5.0\) Firmware<=141217
TP-Link Tl-wr741nd \(5.0\)
TP-Link Tl-wdr3600 \(1.0\) Firmware<=141022
TP-Link Tl-wdr3600 \(1.0\)
TP-Link Archer C7 \(2.0\) Firmware<=141110
TP-Link Archer C7 \(2.0\)
TP-Link Tl-wr841nd \(10.0\) Firmware=150104
TP-Link Tl-wr841nd \(10.0\)
TP-Link Archer C9 \(1.0\) Firmware<=150122
TP-Link Archer C9 \(1.0\)
TP-Link Tl-wr841nd \(9.0\) Firmware<=150104
TP-Link Tl-wr841nd \(9.0\)
TP-Link Archer C8 \(1.0\) Firmware<=141023
TP-Link Archer C8 \(1.0\)
TP-Link Tl-wdr4300 \(1.0\) Firmware<=141113
TP-Link Tl-wdr4300 \(1.0\)
TP-Link Tl-wdr3500 \(1.0\) Firmware<=141113
TP-Link Tl-wdr3500 \(1.0\)
All of the following
TP-Link Tl-wr741nd Firmware<150312
TP-Link TL-WR741ND=5
All of the following
TP-Link TL-WR841N firmware<150310
TP-Link TL-WR841N=9
All of the following
TP-Link Tl-wr740n Firmware<150312
TP-Link TL-WR740N=5
All of the following
TP-Link Archer C5 Firmware<150317
TP-Link Archer C5=1.20
All of the following
TP-Link TL-WR841N firmware<150310
TP-Link TL-WR841N=10
All of the following
TP-Link Tl-wdr3600 Firmware<150302
TP-Link TL-WDR3600=1
All of the following
TP-Link Archer C7 Firmware<150304
TP-Link Archer C7=2
All of the following
TP-Link Tl-wr841nd Firmware<150310
TP-Link TL-WR841ND=10
All of the following
TP-Link Archer C9 Firmware<150302
TP-Link Archer C9=1
All of the following
TP-Link Tl-wr841nd Firmware<150310
TP-Link TL-WR841ND=9
All of the following
TP-Link Archer C8 Firmware<150316
TP-Link Archer C8=1
All of the following
TP-Link Tl-wdr4300 Firmware<150302
TP-Link TL-WDR4300=1
All of the following
TP-Link Tl-wdr3500 Firmware<150302
TP-Link TL-WDR3500=1

Event History

Apr 17, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Apr 22, 2015
Data Sourced
via NVD·01:59 AM
DescriptionSeverityWeaknessAffected Software
Mar 25, 2022
Known Exploited
via CISA·12:00 AM
Mar 25, 2026
News Published
via BleepingComputer·11:11 AM
News Published
via BleepingComputer·11:12 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-3035?

CVE-2015-3035 has been classified with a high severity rating due to its potential to allow directory traversal attacks.

2

How do I fix CVE-2015-3035?

To mitigate CVE-2015-3035, update the firmware of affected TP-Link devices to the latest version that resolves this vulnerability.

3

What devices are affected by CVE-2015-3035?

CVE-2015-3035 impacts several TP-Link Archer and TL-WR devices with specific firmware versions prior to the recommended updates.

4

Can CVE-2015-3035 be exploited remotely?

Yes, CVE-2015-3035 can be exploited remotely by an attacker with knowledge of the vulnerability and proper techniques.

5

What are the potential impacts of CVE-2015-3035?

Exploitation of CVE-2015-3035 can lead to unauthorized access to sensitive files on the affected TP-Link devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203