← Vulnerability feed

Vulnerability record · CVE-2025-9377 · published 29 August 2025

CVE-2025-9377: TP-Link Archer C7 and TL-WR841N Parental Control OS Command Injection

Tp Link · Tl Wr841n Firmware

An OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an authenticated attacker to execute arbitrary commands on the device. Both affected products are end-of-life, so the exposed population is unlikely to receive routine firmware maintenance. The flaw carries a CVSS 4.0 score of 8.6 (High) and was added to CISA KEV, indicating real-world exploitation.

8.6 CVSS 4.0 High CISA KEV since 3 Sep 2025 EPSS 34% · top 1.7% CWE-78 · OS command injection
8.6CVSS 4.0 base score
34%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es).

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows authenticated remote command execution with high impact and is confirmed exploited in CISA KEV, though it requires prior administrative credentials and affects EOL devices.

What it is

An OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an authenticated attacker to execute arbitrary commands on the device. Both affected products are end-of-life, so the exposed population is unlikely to receive routine firmware maintenance. The flaw carries a CVSS 4.0 score of 8.6 (High) and was added to CISA KEV, indicating real-world exploitation.

Impact

An attacker with valid credentials gains remote command execution on the router, enabling full compromise of confidentiality, integrity and availability of the device. That access can be used to alter router configuration, intercept or redirect traffic, or pivot into the connected network.

Attack surface

The vulnerability is reachable over the network via the Parental Control page (AV:N, AC:L). It requires high privileges, meaning the attacker must already hold valid administrative credentials; no user interaction is needed.

Exploitation

CVE-2025-9377 was added to CISA KEV on 2025-09-03 with a remediation due date of 2025-09-24, confirming known exploitation in the wild. EPSS gives a 30-day exploitation probability of roughly 33.5% (98th percentile), and CISA lists no known ransomware campaign use.

What to do

  • Apply the vendor patch referenced in TP-Link FAQ 4365 for Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 (firmware 241108 or later); patch immediately given KEV status.
  • If patching is not possible in the short term, replace the EOL devices with supported models, as TP-Link recommends.
  • Restrict administrative access to the router web interface to trusted management networks and disable remote/WAN-side administration.
  • Change default and weak admin credentials, enforce unique strong passwords, and rotate them if compromise is suspected.
  • If neither patching nor replacement is feasible, isolate the devices on a segmented network and monitor for unauthorized configuration changes.

Detection

  • Monitor router and upstream logs for access to the Parental Control page followed by unexpected command execution or shell-like activity.
  • Alert on anomalous outbound connections or DNS changes originating from the router, which may indicate post-exploitation use.
  • Audit router configuration for unauthorized changes to parental control, DNS, firewall or port-forwarding settings.
  • Track firmware versions of Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 in asset inventory and flag any device below 241108.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-9377 to the Known Exploited Vulnerabilities catalog on 3 September 2025 as "TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 September 2025.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-9377 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-33538TP-Link router web interface command injection in WlanNetworkRpmTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection flaw in the /userRpm/WlanNetworkRpm component of the route…KEVEPSS 42%analysed7.5CVE-2015-3035TP-Link router directory traversal allows unauthenticated file readA path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by plac…KEVEPSS 84%analysed6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed9.8CVE-2022-25073Tp-link tl-wr841n firmware out-of-bounds write vulnerabilityTL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthent…EPSS 13%9.8CVE-2022-0162Tp-link tl-wr841n firmware cleartext transmission vulnerabilityThe vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in…EPSS 0.67%9.8CVE-2020-35575Tp-link wa901nd firmware vulnerabilityA password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web pan…EPSS 7.6%9.8CVE-2018-12575Tp-link tl-wr841n firmware improper authentication vulnerabilityOn TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of auth…EPSS 2.9%9.8CVE-2018-11714TP-Link router CGI session handling bypass allows unauthenticated actionsTP-Link TL-WR840N v5 and TL-WR841N v13 routers mishandle sessions on the /cgi/ path. Sending a Referer header of http://192.168.0.1/mainFrame.htm cau…EPSS 68%analysed

Source: NIST National Vulnerability Database (record CVE-2025-9377), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.