CVE-2015-3035
TP-Link Multiple Archer Devices Directory Traversal Vulnerability
Description
CVE-2015-3035 is a high-severity path traversal vulnerability affecting TP-Link Multiple Archer Devices. Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/. An attacker can exploit this flaw without authentication over the network. CISA has added this vulnerability to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 92.86% (99.8th percentile) indicates a significantly elevated exploitation probability.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr741nd firmware | < 150312 |
| tp-link | tl-wr841n firmware | < 150310 |
| tp-link | tl-wr740n firmware | < 150312 |
| tp-link | archer c5 firmware | < 150317 |
| tp-link | tl-wdr3600 firmware | < 150302 |
| tp-link | archer c7 firmware | < 150304 |
| tp-link | tl-wr841nd firmware | < 150310 |
| tp-link | archer c9 firmware | < 150302 |
| tp-link | archer c8 firmware | < 150316 |
| tp-link | tl-wdr4300 firmware | < 150302 |
| tp-link | tl-wdr3500 firmware | < 150302 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References
- http://packetstormsecurity.com/files/131378/TP-LINK-Local-File-Disclosure.html(Exploit, Third Party Advisory, VDB Entry)
- http://seclists.org/fulldisclosure/2015/Apr/26(Exploit, Mailing List, Third Party Advisory)
- http://www.securityfocus.com/archive/1/535240/100/0/threaded(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securityfocus.com/bid/74050(Broken Link, Third Party Advisory, VDB Entry)
- http://www.tp-link.com/en/download/Archer-C5_V1.20.html#Firmware(Product)
- http://www.tp-link.com/en/download/Archer-C7_V2.html#Firmware(Product)
- http://www.tp-link.com/en/download/Archer-C8_V1.html#Firmware(Product)
- http://www.tp-link.com/en/download/Archer-C9_V1.html#Firmware(Product)
- http://www.tp-link.com/en/download/TL-WDR3500_V1.html#Firmware(Product)
- http://www.tp-link.com/en/download/TL-WDR3600_V1.html#Firmware(Product)
- http://www.tp-link.com/en/download/TL-WDR4300_V1.html#Firmware(Product)
- http://www.tp-link.com/en/download/TL-WR740N_V5.html#Firmware(Product)
- http://www.tp-link.com/en/download/TL-WR741ND_V5.html#Firmware(Product)
- http://www.tp-link.com/en/download/TL-WR841ND_V9.html#Firmware(Product)
- http://www.tp-link.com/en/download/TL-WR841N_V9.html#Firmware(Product)
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150410-0_TP-Link_Unauthenticated_local_file_disclosure_vulnerability_v10.txt(Exploit, Not Applicable)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3035(US Government Resource)
Weakness Type
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Path Traversal (also known as Directory Traversal) is a vulnerability that occurs when software uses external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory, but fails to properly neutralize special elements such as ".. In the case of CVE-2015-3035, this weakness allows attackers to compromise TP-Link Multiple Archer Devices systems.
Learn more: CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Impact Analysis
CVE-2015-3035 carries a CVSS 3.1 base score of 7.5 (HIGH), reflecting the serious risk it poses to affected environments. Successful exploitation can lead to complete compromise of data confidentiality, no direct integrity impact, and no direct availability impact. The attack vector is network-based with low complexity, meaning exploitation is straightforward and can be reliably repeated. Organizations running TP-Link Multiple Archer Devices face tangible risk of unauthorized access, data breaches, and operational disruption if this vulnerability remains unpatched.
Exploit Maturity
CVE-2015-3035 is listed in the CISA Known Exploited Vulnerabilities catalog with a remediation deadline of 2022-04-15, confirming that real-world exploitation has been observed. The EPSS score of 92.86% (99.8th percentile) places this vulnerability among those most likely to be exploited. Public exploit code is available in vulnerability databases, lowering the barrier for attackers and increasing the urgency of remediation.
Remediation
- Apply updates per vendor instructions. This is the CISA-mandated remediation action and should be prioritized immediately.
- If patches cannot be applied immediately, restrict network access to the affected Multiple Archer Devices management interfaces to only trusted administrative networks using firewall rules or access control lists.
- Monitor vendor security advisories for additional updates and ensure a patch management process is in place for timely deployment.
- Conduct a thorough review of affected systems for signs of prior compromise, including unexpected user accounts, modified configurations, and unusual network activity.
- Implement defense-in-depth measures including network segmentation, intrusion detection systems, and continuous security monitoring for the affected infrastructure.
Technical Details
CVE-2015-3035 is exploitable remotely over the network without any prior authentication. Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/. The attack complexity is rated low, meaning no specialized conditions or preparation are needed beyond network access to the target. The scope is unchanged, meaning the impact is confined to the vulnerable component. The CVSS 3.1 base score of 7.5 reflects the combination of these factors and the potential for significant damage to affected systems.
Frequently Asked Questions
Is CVE-2015-3035 being actively exploited?
Yes. CISA has confirmed active exploitation by adding CVE-2015-3035 to the Known Exploited Vulnerabilities catalog. The EPSS score of 92.86% (99.8th percentile) further indicates high exploitation likelihood.
What products are affected by CVE-2015-3035?
CVE-2015-3035 affects TP-Link Multiple Archer Devices. Specifically, affected products include tp-link tl-wr841n (9.0) firmware, tp-link tl-wr740n (5.0) firmware, tp-link archer c5 (1.2) firmware, tp-link tl-wr841n (10.0) firmware, tp-link tl-wr741nd (5.0) firmware, and others.
How do I fix CVE-2015-3035?
Apply updates per vendor instructions. Ensure your systems are updated to the latest patched version. If immediate patching is not feasible, restrict network access to the affected system's management interfaces.
How severe is CVE-2015-3035?
CVE-2015-3035 has a CVSS 3.1 score of 7.5 (HIGH). This is a high-severity vulnerability that poses significant risk and requires prompt remediation. The vulnerability enables unauthenticated remote attackers to potentially compromise affected Multiple Archer Devices systems.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.