Evidence dossier

CVE-2015-3035

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer…

Exploited in the wild (CISA KEV since Mar 25, 2022). NVD reports CVSS 3.1 7.5. EPSS estimates 83.9% exploit likelihood as of Aug 26, 2026.

83.684.4Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

State
PUBLISHED
Published
Apr 17, 2015
Updated
Oct 21, 2025
Evidence coverage
98%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    mitre

    Record text: Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

    Inspect raw assertion
    Field
    container
    Value
    Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: TP-Link Multiple Archer Devices Directory Traversal Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    TP-Link Multiple Archer Devices Directory Traversal Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 83.95% probability · 99.67th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.839480000000; percentile 0.996720000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Mar 25, 2022 · first observed Jul 19, 2026

Exploit likelihood83.95%

FIRST EPSS · score date Aug 26, 2026 · 99.7th percentile · first observed Aug 26, 2026

SeverityCVSS 7.5

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
mitreOriginal assertion
Record text

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

Inspect raw assertion
Field
container
Value
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

TP-Link Multiple Archer Devices Directory Traversal Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
TP-Link Multiple Archer Devices Directory Traversal Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

83.95% probability · 99.67th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.839480000000; percentile 0.996720000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
26Underlying assertions
22Canonical products
13Target assertions
13Constraint assertions

Grouped from 26 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

23 scope groups

mitre · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · HARDWAREtp-linkarcher_c5Environmental constraint · 1 assertions
Version 1.20Canonical identity product-eb39aa0001033f7cdcc96faf14d9c103f06c5f420666bd20cb4422b3efe1372dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:tp-link:archer_c5:1.20:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    72ed6515-1455-4688-ad62-4388267deaf0
NVD CPE · OPERATING SYSTEMtp-linkarcher_c5_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 150317)Canonical identity product-9e4088ca85f299f6e18c3acd1811c2957737bdec04253ea2563babf4098a13c5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:tp-link:archer_c5_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150317
    Match ID
    0cb19ae9-e2b4-41ad-a998-8f8169799acf
NVD CPE · HARDWAREtp-linkarcher_c7Environmental constraint · 1 assertions
Version 2Canonical identity product-2e16b6f1fcca849395b8b025fb24ab1add004eb5b94d441e141be45811fbf010Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:tp-link:archer_c7:2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    41b6a810-b462-4c02-a322-a91cc4161e96
NVD CPE · OPERATING SYSTEMtp-linkarcher_c7_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 150304)Canonical identity product-e1eea748046f3ad7b0f4f2e495731897abf6035a3375b47ba75de8da6a1aef02Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:tp-link:archer_c7_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150304
    Match ID
    058f1d4f-f32e-46b1-9af0-bd8415723f7e
NVD CPE · HARDWAREtp-linkarcher_c8Environmental constraint · 1 assertions
Version 1Canonical identity product-ca6162510298c9fafe35799aed9448e9cfd97acfaaffe6cf2aaf1f720647f533Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:tp-link:archer_c8:1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7cc206ac-5379-4a87-8da7-9d1a006613e4
NVD CPE · OPERATING SYSTEMtp-linkarcher_c8_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 150316)Canonical identity product-6bce8af06065d24c4f5b9027198098f2d0ed650dd081fb6e16e689c54785e37bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:tp-link:archer_c8_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150316
    Match ID
    af0bc274-5fcd-4d50-a3db-0323aeb54f8d
NVD CPE · HARDWAREtp-linkarcher_c9Environmental constraint · 1 assertions
Version 1Canonical identity product-787cb26654a8d4cdb0009f4b9a90a3796c8cb80383b7627cde5388f21355708cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:tp-link:archer_c9:1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9d04216f-1d64-4ea2-9964-e1479140ed95
NVD CPE · OPERATING SYSTEMtp-linkarcher_c9_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 150302)Canonical identity product-f85fef8bebb52b7146b5b7287451879b8f1eb4c4ef62e39ef02e3200551c6b33Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:tp-link:archer_c9_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150302
    Match ID
    ac967456-148e-4810-836b-42184997f8dd
NVD CPE · HARDWAREtp-linktl-wdr3500Environmental constraint · 1 assertions
Version 1Canonical identity product-9573d3b1806da9db236bf878104e31805df08b71e3f77d3e6e9120912f5fd86cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:tp-link:tl-wdr3500:1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    12 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e1641ad6-741d-466f-ac21-9c0e75dfde65
NVD CPE · OPERATING SYSTEMtp-linktl-wdr3500_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 150302)Canonical identity product-14f9090c2f3e2470a171aa3bf8d532be25e4fad0376768df87e5f1a147b75f7aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:tp-link:tl-wdr3500_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150302
    Match ID
    08196b78-4434-47cb-b204-fd01ac649488
NVD CPE · HARDWAREtp-linktl-wdr3600Environmental constraint · 1 assertions
Version 1Canonical identity product-aa453e920853ac878ed006d61353007467010f01f984ba2601568b832072d57bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:tp-link:tl-wdr3600:1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6da54b6f-bca1-4322-b628-43bff4ab26c9
NVD CPE · OPERATING SYSTEMtp-linktl-wdr3600_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 150302)Canonical identity product-3fa282c27a138edc50807b411452cb94d11e89900e40647a643faaa11a761cccLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:tp-link:tl-wdr3600_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150302
    Match ID
    38507261-2931-448d-b06d-2eda1b84a9af
NVD CPE · HARDWAREtp-linktl-wdr4300Environmental constraint · 1 assertions
Version 1Canonical identity product-2b0983f94385e0edc04a5203b67a60243ba8b2e5b1ec775ac0977b659e5dbe94Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:tp-link:tl-wdr4300:1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8ff17499-d24f-47b5-8299-54efdd22e37a
NVD CPE · OPERATING SYSTEMtp-linktl-wdr4300_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 150302)Canonical identity product-c5ad49e8fcb6b519e00914e8908534cdee526b5c4011c44a7c24d2d0d3abd80cLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:tp-link:tl-wdr4300_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150302
    Match ID
    bea0ba45-3662-4764-b2c4-8d518f5e4fbd
NVD CPE · HARDWAREtp-linktl-wr740nEnvironmental constraint · 1 assertions
Version 5Canonical identity product-d856782f5b40995b57b0f1339c92aa570ff50f70f7b282a17632dfbbc45a517eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:tp-link:tl-wr740n:5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3e92fbca-8d75-4080-8586-cf14eb7db1fb
NVD CPE · OPERATING SYSTEMtp-linktl-wr740n_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 150312)Canonical identity product-24d04b69397dfeb5ba34d12d7054e5c4374d31dba14cea336e19ad17b9915870Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:tp-link:tl-wr740n_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150312
    Match ID
    35304b45-f209-4b30-bbc7-182d3183f9d2
NVD CPE · HARDWAREtp-linktl-wr741ndEnvironmental constraint · 1 assertions
Version 5Canonical identity product-c7cd649899f4ee96d5d3edd829ae91be7a2606e8d523cf966acdcb39fb7b6de4Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:tp-link:tl-wr741nd:5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4f28b389-93a9-4f55-b060-c2f02656dfc6
NVD CPE · OPERATING SYSTEMtp-linktl-wr741nd_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 150312)Canonical identity product-a7d57b3fe0542b0a8977f0fa0a21dabae6853388b732060e26644969a8d91ff6Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:tp-link:tl-wr741nd_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150312
    Match ID
    1850531e-2635-4182-8a80-ee2e8508a1c8
NVD CPE · HARDWAREtp-linktl-wr841nEnvironmental constraint · 2 assertions
Version 10; Version 9Canonical identity product-afe079d295eb0172f77ccb0bf344cffaff32f51eed83f0661820a02f614a835bLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:tp-link:tl-wr841n:10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    605fa887-700c-4a7e-a253-e672d5554737
  2. cpe:2.3:h:tp-link:tl-wr841n:9:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    115af4ed-a740-45ce-87ea-93d696a9d373
NVD CPE · HARDWAREtp-linktl-wr841ndEnvironmental constraint · 2 assertions
Version 10; Version 9Canonical identity product-0a41b946e97d1740035d0ed9a27470f42f77d07027b6c78eefb202b905a56d3dLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:tp-link:tl-wr841nd:10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    02427a8c-d815-4be1-b96d-d1c326281ceb
  2. cpe:2.3:h:tp-link:tl-wr841nd:9:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e48e745-0cab-412c-8b52-1f834d72f0cf
NVD CPE · OPERATING SYSTEMtp-linktl-wr841nd_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (< 150310)Canonical identity product-d765c7c1f3da5cd0226ffa7026873c298f2e72ae4c662125d00bb89abab02472Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:tp-link:tl-wr841nd_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150310
    Match ID
    2c07c05e-7770-4ecd-976e-fac3d1aa6b42
  2. cpe:2.3:o:tp-link:tl-wr841nd_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150310
    Match ID
    2c07c05e-7770-4ecd-976e-fac3d1aa6b42
NVD CPE · OPERATING SYSTEMtp-linktl-wr841n_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (< 150310)Canonical identity product-d058d3adc752ef645021364b044603ee3e3e85e2803ed68bbcb5339a00fd9b14Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:tp-link:tl-wr841n_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150310
    Match ID
    85d83801-febd-4657-ba64-6a50a8c6c92f
  2. cpe:2.3:o:tp-link:tl-wr841n_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 150310
    Match ID
    85d83801-febd-4657-ba64-6a50a8c6c92f

Affected-product evidence

Accepted scope and product mapping

11 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-14f9090c2f3e2470a171aa3bf8d532be25e4fad0376768df87e5f1a147b75f7a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
90f0d557-2168-4f6c-a986-425837ff347c
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-24d04b69397dfeb5ba34d12d7054e5c4374d31dba14cea336e19ad17b9915870

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
60e9bf7f-45a1-4131-bc74-6e182db924b1
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-3fa282c27a138edc50807b411452cb94d11e89900e40647a643faaa11a761ccc

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b2bdacc3-2b10-456d-933c-5e7b9e555783
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-6bce8af06065d24c4f5b9027198098f2d0ed650dd081fb6e16e689c54785e37b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
17c34297-dc68-4815-8380-1eff77d486f4
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-9e4088ca85f299f6e18c3acd1811c2957737bdec04253ea2563babf4098a13c5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2acf9611-ad98-4712-8e6f-bb4d5ed00848
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-a7d57b3fe0542b0a8977f0fa0a21dabae6853388b732060e26644969a8d91ff6

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e370c39f-29a4-41aa-80f5-75f7c4dcfcdd
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-c5ad49e8fcb6b519e00914e8908534cdee526b5c4011c44a7c24d2d0d3abd80c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
889e5781-302b-483f-bd1c-38c5031aadd1
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-d058d3adc752ef645021364b044603ee3e3e85e2803ed68bbcb5339a00fd9b14

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
22453e45-5deb-4411-a67e-ab1960f9c3d08d66178e-9c60-4c02-a6f7-010c99230b92
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-d765c7c1f3da5cd0226ffa7026873c298f2e72ae4c662125d00bb89abab02472

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4d145acc-124f-4bf8-81a2-9fc8e1897664d5b8e359-e7b8-4c7f-b086-4f1cbb344e94
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-e1eea748046f3ad7b0f4f2e495731897abf6035a3375b47ba75de8da6a1aef02

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5c98667b-37e4-4ded-9a4b-83a67408c4bb
Mapping establishedEvidence supported

vendor-6d5b48b0c21af0da9be49aa188af51c6538c4a9c1ddc79dea278af6c8121a3e1 · product-f85fef8bebb52b7146b5b7287451879b8f1eb4c4ef62e39ef02e3200551c6b33

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
bac21755-fc53-48b7-8f8d-8900ada5f488
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
18fe1e6b-e888-42ee-8526-df6eca973c52

Assessments

CVSS by origin

7.5
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.8
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:C/I:N/A:N
7.5
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Direct CVE/CNA normalized decisions

7.5Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Validation
Valid match
Recomputed
7.5
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.