Executive brief
TP-Link Archer C7 and TL-WR841N routers contain a security flaw in their Parental Control management page. An attacker with administrative access can take full control of the device to monitor traffic or disrupt internet services. Because these devices are end-of-life, users are strongly encouraged to replace them with modern hardware.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Parental Control interface of several TP-Link router models. The flaw allows an authenticated attacker with high privileges to execute arbitrary system commands via the web management interface. This can lead to full remote code execution (RCE) on the underlying operating system. The vulnerability is confirmed to be exploited in the wild. While the products are end-of-life (EoL), TP-Link has released a patch (version 241108) for users unable to immediately replace the hardware.
Affected products
- TP-Link Archer C7 (EU) V2 Before 241108
- TP-Link TL-WR841N V9 Before 241108
- TP-Link TL-WR841ND V9 Before 241108
Timeline
- 2025-08-29: disclosed: Initial disclosure by TP-Link
- 2025-09-03: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-11-08: patched: Firmware version 241108 released