TP-LINK Archer C5等都是中国普联(TP-LINK)公司的无线路由器产品。 多款TP-LINK产品中存在目录遍历漏洞,该漏洞源于login/ URI没有充分过滤PATH_INFO值。远程攻击者可借助目录遍历字符‘..’利用该漏洞读取任意文件。以下产品及版本受到影响:使用150317之前版本固件的TP-LINK Archer C5(硬件版本:1.2版本),使用150304之前版本固件的C7(硬件版本:2.0版本),使用150316之前版本固件的C8(硬件版本:1.0版本),使用150302之前
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | TP-LINK is susceptible to local file inclusion in these products: Archer C5 (1.2) with firmware before 150317, Archer C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310. Because of insufficient input validation, arbitrary local files can be disclosed. Files that include passwords and other sensitive information can be accessed. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2015/CVE-2015-3035.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2015-0845 | Six Apart Movable Type 格式化字符串漏洞 | |
| CVE-2015-1318 | Ubuntu Apport 安全漏洞 | |
| CVE-2015-1852 | OpenStack keystone 代码问题漏洞 | |
| CVE-2015-1856 | OpenStack Object Storage 安全漏洞 | |
| CVE-2015-0530 | EMC NetWorke nsr_render_log 缓冲区溢出漏洞 | |
| CVE-2015-0691 | Cisco Secure Desktop Cache Cleaner JAR文件安全漏洞 | |
| CVE-2015-0695 | Cisco ASR 9000 Cisco IOS XR 拒绝服务漏洞 | |
| CVE-2015-0700 | Cisco Secure Access Control Server Solution Engine 跨站请求伪造漏洞 | |
| CVE-2015-0937 | Blue Coat Malware Systems Analysis Appliance 跨站脚本漏洞 | |
| CVE-2015-0938 | Blue Coat Malware Systems Analysis Appliance 安全漏洞 |
No comments yet