Vulnerability record · CVE-2025-9377 · published 29 August 2025
CVE-2025-9377: TP-Link Archer C7 and TL-WR841N Parental Control OS Command Injection
Tp Link · Tl Wr841n Firmware
An OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an authenticated attacker to execute arbitrary commands on the device. Both affected products are end-of-life, so the exposed population is unlikely to receive routine firmware maintenance. The flaw carries a CVSS 4.0 score of 8.6 (High) and was added to CISA KEV, indicating real-world exploitation.
Description
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es).
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityThe flaw allows authenticated remote command execution with high impact and is confirmed exploited in CISA KEV, though it requires prior administrative credentials and affects EOL devices.
What it is
An OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an authenticated attacker to execute arbitrary commands on the device. Both affected products are end-of-life, so the exposed population is unlikely to receive routine firmware maintenance. The flaw carries a CVSS 4.0 score of 8.6 (High) and was added to CISA KEV, indicating real-world exploitation.
Impact
An attacker with valid credentials gains remote command execution on the router, enabling full compromise of confidentiality, integrity and availability of the device. That access can be used to alter router configuration, intercept or redirect traffic, or pivot into the connected network.
Attack surface
The vulnerability is reachable over the network via the Parental Control page (AV:N, AC:L). It requires high privileges, meaning the attacker must already hold valid administrative credentials; no user interaction is needed.
Exploitation
CVE-2025-9377 was added to CISA KEV on 2025-09-03 with a remediation due date of 2025-09-24, confirming known exploitation in the wild. EPSS gives a 30-day exploitation probability of roughly 33.5% (98th percentile), and CISA lists no known ransomware campaign use.
What to do
- Apply the vendor patch referenced in TP-Link FAQ 4365 for Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 (firmware 241108 or later); patch immediately given KEV status.
- If patching is not possible in the short term, replace the EOL devices with supported models, as TP-Link recommends.
- Restrict administrative access to the router web interface to trusted management networks and disable remote/WAN-side administration.
- Change default and weak admin credentials, enforce unique strong passwords, and rotate them if compromise is suspected.
- If neither patching nor replacement is feasible, isolate the devices on a segmented network and monitor for unauthorized configuration changes.
Detection
- Monitor router and upstream logs for access to the Parental Control page followed by unexpected command execution or shell-like activity.
- Alert on anomalous outbound connections or DNS changes originating from the router, which may indicate post-exploitation use.
- Audit router configuration for unauthorized changes to parental control, DNS, firewall or port-forwarding settings.
- Track firmware versions of Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 in asset inventory and flag any device below 241108.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-9377 to the Known Exploited Vulnerabilities catalog on 3 September 2025 as "TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 September 2025.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tp-link.com/us/support/faq/4308/ | Product |
| https://www.tp-link.com/us/support/faq/4365/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-9377 | US Government Resource |
Track CVE-2025-9377 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-9377), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.