CVE-2025-9377
Description
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9.
This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108.
Both products have reached the status of EOL (end-of-life).
It's recommending to
purchase the new
product to ensure better performance and security. If replacement is not
an option in the short term, please use the second reference link to
download and install the patch(es).
Summary dbcve.org
Authenticated remote command execution vulnerability in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers. An attacker with valid administrative credentials can inject and execute arbitrary operating system commands through insufficient input sanitization in the Parental Control functionality, achieving full device compromise.
Mitigation
Apply firmware version 241108 or later if available; otherwise replace EOL devices with supported models, as TP-Link has discontinued these products.