CVE-2025-9377 is an authenticated remote command execution vulnerability in TP-Link router web interfaces that allows network-based exploitation of internet-facing devices. CISA has confirmed active exploitation and added it to the KEV catalog.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-08-29
Added to CISA KEV: 2025-09-03 5 DAYS BETWEEN CVE AND KEV
Description CVE-2025-9377 is an authenticated remote command execution (RCE) vulnerability affecting the Parental Control page of TP-Link Archer C7 (EU) V2 and TL-WR841N/ND (MS) V9 routers. Successful exploitation allows an attacker to execute arbitrary commands remotely, gaining control over the affected device.
Description. The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 ...
CISA flags TP-Link flaws CVE-2023-50224 and CVE-2025-9377 as exploited, urging fixes by Sept 24, 2025.
CISA has issued an urgent warning regarding critical vulnerabilities in popular TP-Link router that are currently being actively exploited.
CVE-2025-50224 is a vulnerability that allows an attacker to steal passwords from the router and CVE-2025-9377 is a known Parental Control ...