HIGH

CVE-2025-9377

Tp-link Tl Wr841n Firmware 2025-08-29 CVSS v3.1
CVSS
7.2
KEV

Description

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9.

This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108.

Both products have reached the status of EOL (end-of-life).
It's recommending to

purchase the new
product to ensure better performance and security. If replacement is not
an option in the short term, please use the second reference link to
download and install the patch(es).

Summary dbcve.org

Authenticated remote command execution vulnerability in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers. An attacker with valid administrative credentials can inject and execute arbitrary operating system commands through insufficient input sanitization in the Parental Control functionality, achieving full device compromise.

Mitigation

Apply firmware version 241108 or later if available; otherwise replace EOL devices with supported models, as TP-Link has discontinued these products.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

33.52%
Probability of exploitation in next 30 days
98.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE