SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP TP-Link Router Web Server directory traversal attempt
This is looking for access to the /fs endpoint that contains .. in it's path (i.e. /fs/../../../etc/passwd).
This rule alerts on a directory traversal attempt through the TP-LINK web interface.
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group
No rule groups
No information provided
Technique: Exfiltration Over Web Service
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org