CVE-2012-5687

TP-LINK TL-WR841N <3.13.9 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.

Exploits (2)

exploitdb WRITEUP
webappshardware
https://www.exploit-db.com/exploits/24504
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/tplink_traversal_noauth.rb

Scores

EPSS 0.6748
EPSS Percentile 98.6%

Details

CWE
CWE-22
Status published
Products (2)
tp-link/tl-wr841n
tp-link/tl-wr841n_firmware < 3.13.9
Published Nov 01, 2012
Tracked Since Feb 18, 2026