CVE 8.6 HIGH

Authenticated RCE via Parental Control command injection_CVE-2025-9377

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9.

This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108.

Both products have reached the status of EOL (end-of-life).
It's recommending to

purchase the new
product to ensure better performance and security. If replacement is not
an option in the short term, please use the second reference link to
download and install the patch(es).

Basic Information

ID CVE-2025-9377
Source TPLink
Published Aug 29, 2025 at 17:30
Modified Aug 29, 2025 at 18:21

Affected Product

Vendor TP-Link Systems Inc.
Product Archer C7(EU) V2
Affected Versions TP-Link Systems Inc. Archer C7(EU) V2 0
TP-Link Systems Inc. TL-WR841N/ND(MS) V9 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.