boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-9377

TP-Link Systems Inc. Archer C7(EU) V2 — Authenticated RCE via Parental Control command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .3352   98.3   YES
AFFECTED
  Product              Versions     Fixed
  Archer C7(EU) V2     unspecified  —
  TL-WR841N/ND(MS) V9  unspecified  —
TIMELINE
  Aug 23  Reserved by TPLink
  Aug 29  Published (CNA: TPLink)
  Sep 3   Added to CISA KEV, remediation due 2025-09-24
CWE-78 · CNA: TPLink · CVSS v4.0 · 3 references · KEV due September 24, 2025

Description

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es).

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 23, 2025ReservedReserved by TPLink
August 29, 2025PublishedPublished (CNA: TPLink)
September 3, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-09-24

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
TP-Link Systems Inc.Archer C7(EU) V2———
TP-Link Systems Inc.TL-WR841N/ND(MS) V9———

Weaknesses

CWE-78

References (3)

Related

Authoritative record: CVE-2025-9377 at cve.org

Vendors: tp-link systems

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-9377 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.