CVE-2012-5687
high · 7.8Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.
7.8
CVSS
68.7%
EPSS (exploit prob.)
99th
EPSS percentile
2012-11-01
Published
AV:N/AC:L/Au:N/C:C/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| tp-link | tl-wr841n | all versions |
| tp-link | tl-wr841n_firmware | <= 3.13.9 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0154.html
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0154.html
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0154.html
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0154.html
- http://packetstormsecurity.org/files/117749/TP-LINK-TL-WR841N-Local-File-Inclusion.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79662
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0154.html
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0154.html
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0154.html
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0154.html
- http://packetstormsecurity.org/files/117749/TP-LINK-TL-WR841N-Local-File-Inclusion.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79662
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-5687