CVE-2025-9377 is an authenticated remote command execution (RCE) vulnerability found in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers. These products are End-of-Life (EOL), and users are advised to upgrade to newer devices or apply available patches. The vulnerability carries a CVSS score of 7.2 (High), indicating a significant risk. It requires high privileges (PR:H) for exploitation but has low attack complexity (AC:L) and can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). This CVE is actively exploited (KEV: Yes) and has garnered substantial community attention with 13 mentions and 2 media articles, despite no public exploit code being readily available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 241108CPE matchmatch criteria | cpe:2.3:o:tp-link:tl-wr841n_firmware:*:*:*:*:*:*:*:* | ||
< 241108CPE matchmatch criteria | cpe:2.3:o:tp-link:tl-wr841nd_firmware:*:*:*:*:*:*:*:* | ||
< 241108CPE matchmatch criteria | cpe:2.3:o:tp-link:archer_c7_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.