CVE-2012-5687

TP-LINK TL-WR841N <3.13.9 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.

Exploits (2)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/tplink_traversal_noauth.rb
exploitdb WRITEUP
webappshardware
https://www.exploit-db.com/exploits/24504

Scores

EPSS 0.6748
EPSS Percentile 98.5%

Classification

CWE
CWE-22
Status draft

Affected Products (2)

tp-link/tl-wr841n
tp-link/tl-wr841n_firmware < 3.13.9

Timeline

Published Nov 01, 2012
Tracked Since Feb 18, 2026