S4E just found an informational finding from web application firewall (waf) detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2015-3035 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in various TP-LINK devices.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
3.8k
Continuously Checked
assets under CS
4
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2015-3035
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

TP-LINK is a prominent brand in the field of networking products. The company offers a range of routers and modems that are widely popular among businesses and individuals alike. These devices are designed to provide high speed and reliable internet connectivity to their users. TP-LINK's Archer C5 (1.2), Archer C7 (2.0), Archer C8 (1.0), Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), TL-WDR4300 (1.0), TL-WR740N (5.0), TL-WR741ND (5.0), TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) are some of their popular offerings.

One of these devices, the TP-LINK Archer C5 (1.2), Archer C7 (2.0), Archer C8 (1.0), Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), TL-WDR4300 (1.0), TL-WR740N (5.0), TL-WR741ND (5.0), TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) has been found to have a severe vulnerability. This vulnerability is known as CVE-2015-3035 and is related to directory traversal. The vulnerability exists in the firmware of these devices before versions 150317, 150304, 150316, 150302, and 150312, respectively.

Exploiting this vulnerability, a remote attacker can potentially read arbitrary files on the device by adding a ".." (dot dot) to the end of the URL before the "login/" keyword. This can result in the attacker gaining access to sensitive information, such as login credentials. The attacker can also use this access to execute arbitrary code on the device, leading to further damage.

It is important to note that vulnerability scanning and management platforms like s4e.io provide comprehensive and easy-to-use solutions that can help businesses and individuals protect their digital assets from vulnerabilities such as CVE-2015-3035. With the help of such platforms, the users can quickly identify and mitigate vulnerabilities in their devices and networks, providing them with peace of mind and a strong foothold against cyber attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of TP-LINK Archer C5 (1.2), Archer C7 (2.0), Archer C8 (1.0), Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), TL-WDR4300 (1.0), TL-WR740N (5.0), TL-WR741ND (5.0), TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) devices can take the following precautions:

  • Update the device firmware to the latest version.
  • Disable remote access to the device.
  • Change the default login credentials of the device to a strong, unique password.
  • Enable multi-factor authentication, if available.
  • Use a VPN to access the device remotely.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-3035 scanner - Local File Inclusion (LFI) vulnerability in various TP-LINK devices | S4E