Skip to content
COOEY

EXPOSURES › CVE-2015-3035

CVE-2015-3035

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-3035 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

TP-Link Archer routers suffer a directory traversal flaw allowing remote attackers to read arbitrary files, now actively exploited and cataloged by CISA.

A directory traversal vulnerability in TP-Link Archer devices lets attackers read arbitrary files via path manipulation, exposing sensitive data and enabling further compromise. This flaw is actively exploited in the wild and listed in CISA's KEV catalog, indicating a severe compliance and operational risk for organizations using these devices. DIBs should immediately replace affected hardware and patch firmware to prevent data exfiltration and lateral movement.

Shame score — A critical, actively exploited vulnerability in widely deployed consumer routers that TP-Link failed to patch promptly, leading to widespread exploitation and inclusion in CISA's KEV catalog.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.