SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP TP-Link Router Web Server directory traversal attempt
This is looking for access to the /login or /loginFs endpoints that contain .. in their path (i.e. /login/../../../etc/passwd).
This rule alerts on a directory traversal attempt through the TP-LINK web interface.
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group
No rule groups
No information provided