CVE-2025-9377
9.5 CISA KEVTP-Link · Archer C7(EU) and TL-WR841N/ND(MS)
An authenticated remote command injection vulnerability exists in the Parental Control page of specific TP-Link routers, allowing for arbitrary code execution.
Executive summary
This critical remote command injection vulnerability in TP-Link Archer C7 and TL-WR841 routers is currently being exploited in the wild to facilitate botnet recruitment and credential-spraying attacks.
Vulnerability
The flaw resides in the Parental Control configuration page and allows an authenticated attacker with administrative privileges to execute arbitrary OS commands. The vulnerability stems from improper neutralization of special elements used in system commands.
Business impact
Successful exploitation leads to full system compromise, granting an attacker total control over the affected router. Given the CVSS score of 9.5, this poses a severe risk, as the device can be used as a pivot point for internal network reconnaissance or to join the Quad7 botnet for password-spraying attacks against cloud infrastructure like Microsoft 365. Because these devices have reached end-of-life status, they are no longer receiving ongoing security support, significantly increasing the risk of persistent, unpatchable compromise.
Remediation
Immediate Action: Apply firmware version 241108 or later immediately if available via the vendor support site. Given that these devices are end-of-life, the most effective remediation is to decommission and replace the hardware with currently supported models.
Proactive Monitoring: Monitor network traffic for unusual outbound connections from router management interfaces or unexpected authentication attempts originating from the router IP addresses toward external mail or authentication portals.
Compensating Controls: Restrict access to the router management interface to a dedicated management VLAN or a specific trusted administrative IP address to prevent unauthorized internal access.
Exploitation status
Public Exploit Available: Yes.
Analyst recommendation
The combination of a critical CVSS score, confirmed presence in the CISA KEV catalog, and active exploitation in the wild necessitates immediate intervention. Organizations still utilizing these TP-Link models must prioritize their removal from the network environment. If immediate replacement is not feasible, apply the provided firmware patch at once and isolate the devices from all critical network segments to prevent further exploitation.