CVE-2025-9377
Last modified
CVE-2025-9377 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es).. CISA has confirmed active exploitation in the wild. EPSS estimates a 11.75% chance of exploitation in the next 30 days.
Description
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es).
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wr841n Firmware | < 241108 |
| Tp-Link | Tl-Wr841nd Firmware | < 241108 |
| Tp-Link | Archer C7 Firmware | < 241108 |
References
- https://www.tp-link.com/us/support/faq/4365/Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-9377US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-9377?
How severe is CVE-2025-9377?
How do I fix CVE-2025-9377?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-9368A security issue exists within 432ES-IG3 Series A, which aff…8.7
- CVE-2025-9371The Betheme theme for WordPress is vulnerable to Stored Cros…6.4
- CVE-2025-9372The Ultimate Multi Design Video Carousel plugin for WordPres…5.5
- CVE-2025-9374The Ultimate Tag Warrior Importer plugin for WordPress is vu…4.3
- CVE-2025-9375XML Injection vulnerability in xmltodict allows Input Data M…6.9
- CVE-2025-9376The Block Bad Bots and Stop Bad Bots Crawlers and Spiders an…6.5
- CVE-2025-9378The Vayu Blocks – Website Builder for the Block Editor plugi…6.4
- CVE-2025-9379A vulnerability was determined in Belkin AX1800 1.1.00.016. …8.6
- CVE-2025-9380A vulnerability was identified in FNKvision Y215 CCTV Camera…7.8
- CVE-2025-9381A security flaw has been discovered in FNKvision Y215 CCTV C…1.6
- CVE-2025-9382A weakness has been identified in FNKvision Y215 CCTV Camera…6.4
- CVE-2025-9383A security vulnerability has been detected in FNKvision Y215…2.5
Are you affected by CVE-2025-9377?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
