Junglewise Threat Intelligence

CVE-2025-9377: TP-Link Archer C7 and TL-WR841N OS command injection in Parental Control

CVE-2025-9377 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2025-09-03

Technologies: TP-Link Multiple Routers, TP-Link TL-WR841N. Vendors: TP-Link.

Executive brief

TP-Link Archer C7 and TL-WR841N routers contain a security flaw in their Parental Control management page. An attacker with administrative access can take full control of the device to monitor traffic or disrupt internet services. Because these devices are end-of-life, users are strongly encouraged to replace them with modern hardware.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Parental Control interface of several TP-Link router models. The flaw allows an authenticated attacker with high privileges to execute arbitrary system commands via the web management interface. This can lead to full remote code execution (RCE) on the underlying operating system. The vulnerability is confirmed to be exploited in the wild. While the products are end-of-life (EoL), TP-Link has released a patch (version 241108) for users unable to immediately replace the hardware.

Affected products

  • TP-Link Archer C7 (EU) V2 Before 241108
  • TP-Link TL-WR841N V9 Before 241108
  • TP-Link TL-WR841ND V9 Before 241108

Timeline

  • 2025-08-29: disclosed: Initial disclosure by TP-Link
  • 2025-09-03: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-11-08: patched: Firmware version 241108 released

Related threats