CVE-2018-3949: TP-Link Tl-r600vpn Firmware
High severity, CVSS 7.5. EPSS: 53.3% chance of exploitation in the next 30 days.
An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A specially crafted URL can cause a directory traversal, resulting in the disclosure of sensitive system files. An attacker can send either an unauthenticated or an authenticated web request to trigger this vulnerability.
Affected products
- TP-Link Tl-r600vpn Firmware: version 1.3.0 only; version 1.2.3 only
Published 2018-12-01. Last modified 2026-06-17.