QID 731277

Date Published: 2024-03-21

QID 731277: TP-Link Router Directory Traversal Vulnerability

TP-LINK routers are vulnerable to local file inclusion vulnerability.

Affected Versions:
TP-LINK Archer C5 (1.2) with firmware before 150317
TP-LINK Archer C7 (2.0) with firmware before 150304
TP-LINK Archer C8 (1.0) with firmware before 150316
TP-LINK Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302
TP-LINK TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312
TP-LINK TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310

QID Detection Logic:
This QID checks for vulnerable installation of TP-Link Router by sending a crafted payload as an HTTP GET request. The payload tries to read files such as '/login/../../../etc/passwd' to check for the vulnerability.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to read arbitrary files from the target system.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Please contact to vendor TP-Link for further patch details.

    Vendor References

    CVEs related to QID 731277

    Software Advisories
    Advisory ID Software Component Link
    TP-Link HomePage URL Logo www.tp-link.com/in/