CVSS v3
7.5
HIGH
EPSS Score
23.4%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A specially crafted URL can cause a directory traversal, resulting in the disclosure of sensitive system files. An attacker can send either an unauthenticated or an authenticated web request to trigger this vulnerability.
An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A specially crafted URL can cause a directory traversal, resulting in the disclosure of sensitive system files. An attacker can send either an unauthenticated or an authenticated web request to trigger this vulnerability.
Active exploitation of CVE-2018-3949 has not been confirmed. The EPSS score is 23.4%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2018-3949 has a CVSS v3 base score of 7.5 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).