CVE-2015-3035
Confirmed PUBLISHEDDirectory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with...
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
- CVE Published
- Apr 17, 2015
- Exploitation Reported
- Mar 25, 2022
- CVSS
- 7.5 High
- EPSS
- —
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| n/a |
n/a
|
n/a |
Affected |
CVE References
- 74050 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/74050
- 20150410 SEC Consult SA-20150410-0 :: Unauthenticated Local File Disclosure in multiple TP-LINK products (CVE-2015-3035) seclists.org · Mailing List http://seclists.org/fulldisclosure/2015/Apr/26
- 20150410 SEC Consult SA-20150410-0 :: Unauthenticated Local File Disclosure in multiple TP-LINK products (CVE-2015-3035) securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/535240/100/0/threaded
- tp-link.com/en/download/Archer-C9_V1.html tp-link.com · CVE Record http://www.tp-link.com/en/download/Archer-C9_V1.html#Firmware
- tp-link.com/en/download/Archer-C7_V2.html tp-link.com · CVE Record http://www.tp-link.com/en/download/Archer-C7_V2.html#Firmware
Show 11 more references
- tp-link.com/en/download/TL-WR740N_V5.html tp-link.com · CVE Record http://www.tp-link.com/en/download/TL-WR740N_V5.html#Firmware
- tp-link.com/en/download/Archer-C5_V1.20.html tp-link.com · CVE Record http://www.tp-link.com/en/download/Archer-C5_V1.20.html#Firmware
- packetstormsecurity.com/files/131378/TP-LINK-Local-File-Disclosure.html packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/131378/TP-LINK-Local-File-Disclo...
- tp-link.com/en/download/TL-WR841N_V9.html tp-link.com · CVE Record http://www.tp-link.com/en/download/TL-WR841N_V9.html#Firmware
- tp-link.com/en/download/TL-WR841ND_V9.html tp-link.com · CVE Record http://www.tp-link.com/en/download/TL-WR841ND_V9.html#Firmware
- tp-link.com/en/download/TL-WDR3600_V1.html tp-link.com · CVE Record http://www.tp-link.com/en/download/TL-WDR3600_V1.html#Firmware
- tp-link.com/en/download/TL-WDR3500_V1.html tp-link.com · CVE Record http://www.tp-link.com/en/download/TL-WDR3500_V1.html#Firmware
- sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/2... sec-consult.com · CVE Record https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_tx...
- tp-link.com/en/download/TL-WR741ND_V5.html tp-link.com · CVE Record http://www.tp-link.com/en/download/TL-WR741ND_V5.html#Firmware
- tp-link.com/en/download/Archer-C8_V1.html tp-link.com · CVE Record http://www.tp-link.com/en/download/Archer-C8_V1.html#Firmware
- tp-link.com/en/download/TL-WDR4300_V1.html tp-link.com · CVE Record http://www.tp-link.com/en/download/TL-WDR4300_V1.html#Firmware
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2022-03-25 00:00 UTC |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2015/CVE-2015-3035.yaml | Apr 25, 2025 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:L/Au:N/C:C/I:N/A:N
Exploitation Status
Exploited in the wild
Recorded 2022-03-25 00:00:00 UTC · CISA
Proof of concept available
Recorded 2026-06-12 14:20:05 UTC · Nuclei Templates
Weaknesses (CWE)
-
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2015/CVE-2015-3035.yaml | Apr 25, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
14:20 UTC about 1 month ago14:20 UTC · about 1 month ago
Public PoC available
Public proof-of-concept code published
-
00:00 UTC about 1 year ago00:00 UTC · about 1 year ago
Nuclei template available
Scanner coverage available
-
00:00 UTC over 4 years ago00:00 UTC · over 4 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
18:00 UTC over 11 years ago18:00 UTC · over 11 years ago
CVE published
Vulnerability disclosed publicly
-
00:00 UTC over 11 years ago00:00 UTC · over 11 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2015-3035
{
"cve_id": "CVE-2015-3035",
"title": "Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware be...",
"affected_vendor": "TP-LINK",
"affected_product": "Archer C5, Archer C7, Archer C8, Archer C9, TL-WDR3500, TL-WDR3600, TL-WDR4300, TL-WR740N, TL-WR741ND, TL-WR841N, TL-WR841ND",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 7.5,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}