EXPOSURES › CVE-2015-3035
CVE-2015-3035
HIGH ⌖ ON CISA KEV · EXPLOITEDTP-Link Archer routers suffer a directory traversal flaw allowing remote attackers to read arbitrary files, now actively exploited and cataloged by CISA.
A directory traversal vulnerability in TP-Link Archer devices lets attackers read arbitrary files via path manipulation, exposing sensitive data and enabling further compromise. This flaw is actively exploited in the wild and listed in CISA's KEV catalog, indicating a severe compliance and operational risk for organizations using these devices. DIBs should immediately replace affected hardware and patch firmware to prevent data exfiltration and lateral movement.
Shame score — A critical, actively exploited vulnerability in widely deployed consumer routers that TP-Link failed to patch promptly, leading to widespread exploitation and inclusion in CISA's KEV catalog.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.