Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-9377
TP-Link Systems Inc. Archer C7(EU) V2 — Authenticated RCE via Parental Control command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N H N H H H 8.6 .3352 98.3 YES
AFFECTED
Product Versions Fixed
Archer C7(EU) V2 unspecified —
TL-WR841N/ND(MS) V9 unspecified —
TIMELINE
Aug 23 Reserved by TPLink
Aug 29 Published (CNA: TPLink)
Sep 3 Added to CISA KEV, remediation due 2025-09-24
Description
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9.
This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108.
Both products have reached the status of EOL (end-of-life).
It's recommending to
purchase the new
product to ensure better performance and security. If replacement is not
an option in the short term, please use the second reference link to
download and install the patch(es).
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 23, 2025 | Reserved | Reserved by TPLink |
| August 29, 2025 | Published | Published (CNA: TPLink) |
| September 3, 2025 | KEV ADDED | Added to CISA KEV, remediation due 2025-09-24 |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| TP-Link Systems Inc. | Archer C7(EU) V2 | — | — | — |
| TP-Link Systems Inc. | TL-WR841N/ND(MS) V9 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-9377 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.