LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-3035: TP-Link Multiple Archer Devices Directory Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-3035 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

CVE-2015-3035 is a directory traversal vulnerability affecting multiple TP-Link Archer devices. It allows a remote attacker to read arbitrary files on the device by supplying path traversal sequences in a request to the login path. For IT and security teams, this matters because routers and similar edge devices often hold configuration data, credentials, or network details; unauthorized file read can expose that information and aid further compromise of the local network.

Public detail is limited to the class of flaw and the high-level attack vector described by CISA. Confirm exact product models, firmware revisions, and fixed versions against the vendor advisory before acting.

How it works

The weakness is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In this case, the device fails to properly sanitize path information supplied in the PATH_INFO portion of a request to the login endpoint. An attacker can insert “..” (dot-dot) sequences to climb out of the intended directory and request files elsewhere on the filesystem.

Because the vulnerability is reachable remotely and does not require authentication according to the CISA summary, an unauthenticated party who can reach the device’s web interface may be able to retrieve arbitrary files. The precise files that can be read, the exact request format beyond the PATH_INFO element, and any additional constraints are not detailed in the provided facts; treat those as items to verify in the vendor advisory and your own testing in a controlled environment.

Am I affected? How to find it in your systems

TP-Link Archer devices are commonly deployed as consumer and small-office/home-office wireless routers and gateways. They typically sit at the network edge, terminating WAN links and providing Wi-Fi and LAN services.

If you lack centralized logging for these devices, enable it where the vendor supports it and retain logs long enough to support incident review.

How to remediate

The primary remediation is to apply the updates provided by the vendor, following the instructions in the official advisory. CISA’s required action is simply to apply updates per vendor instructions.

Confirm the exact fixed versions and any post-update verification steps in the vendor advisory; those details are not supplied in the facts available here.

If you can't patch immediately

When immediate patching is not possible, reduce exposure with compensating controls while you arrange the update.

These measures lower risk but do not eliminate the vulnerability; treat them as temporary.

If your data may have been exposed

Actively exploited vulnerabilities on network devices can lead to broader breaches, including theft of credentials or configuration data that enable lateral movement. Known ransomware use of this specific CVE is not documented in the provided facts. If you suspect the device was reachable and unpatched during the period of exposure, treat any sensitive material that resided on it (configuration backups, stored passwords, certificates, logs) as potentially compromised: rotate credentials, revoke and re-issue certificates, and review downstream systems for unauthorized access. You can also run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts appear in public breach corpora, then proceed with password changes and monitoring as appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTP-Link · Multiple Archer Devices
WeaknessCWE-22
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities