Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.
Exploit:
The following example URIs and exploit code are available:
http://downloads.securityfocus.com/vulnerabilities/exploits/56320.txt