CVE-2025-9377Active Exploitation(tp-link / archer_c7)

MEDIUMCVSS 7.2 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch tp-link archer_c7 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es).

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-09-24. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_c7
  • archer_c7_firmware
  • tl-wr841n
  • tl-wr841n_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-27); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
archer_c7archer_c7_firmwaretl-wr841ntl-wr841n_firmwaretl-wr841ndtl-wr841nd_firmware

3 versions affected across 6 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-27: 1Mentions · 2026-03-22: 1Active Exploitation · 2026-02-27: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-22: 1Technical Details · 2026-02-27: 102-2703-22
Signal classification2 categories
Active Exploitation
150.0%
Patch
150.0%
Classification over time
DateTotalLabels
2026-02-271
Active Exploitation1
2026-03-221
Patch1
Full discourse2 posts
  • 摩女peace🌟🌟🌟银河系。新号,小心假号,这个是真的@peace86774949
    Active Exploitation

    TP-Link 產品的安全性在市場上評價兩極。其產品具備基本加密與NCC認證,但近年來因多項高風險資安漏洞(如 CVE-2023-50224, CVE-2025-9377)遭披露,且曾被指控遭黑客利用,導致其安全性備受爭議。 國家資通安全研究院 國家資通安全研究院 +3 關鍵安全性觀點: 安全漏洞風險: 研究發現多款舊型或特定型號 TP-Link 路由器存在「敏感資訊洩露」和「命令注入」漏洞,已被攻擊者用於建立殭屍網路。 技術與隱私防護: TP-Link 聲明其 Tapo 攝像頭使用安全可靠的 AWS 伺服器,且無「預設密碼」登錄,支援加密傳輸。 政治與背景疑慮: 美國曾因資安風險考慮封殺 TP-Link,指出其設備可能成為中國駭客攻擊工具。 建議操作: 用戶需定期更新韌體、更改預設管理員密碼、停用遠端管理功能以保障安全。 國家資通安全研究院 國家資通安全研究院 +8 總結來說,若能勤於更新韌體並妥善設定,TP-Link 設備可作為一般的家庭網路使用,但若對隱私與中國背景資安風險極度敏感,建議考慮其他品牌。

    Post summary

    TP‑Link routers are affected by CVE‑2023‑50224 and CVE‑2025‑9377, with attackers already exploiting these flaws to create botnets; users are advised to update firmware and change default credentials.

    12403601.4K
    44.7K followersView on X
  • Type00R@rtakemitsuchi
    Patch

    @kamakiri2631 The link in the repost was deleted and the account is frozen. There was a high possibility that the post was a clickbait fake news…The quad7 issue was a new nearly half years ago and tp-link has solved it by releasing patches of CVE-2025-50224 and CVE-2025-9377

    Post summary

    The tweet suggests the original post was clickbait, but notes TP‑Link has already released patches for CVE‑2025‑50224 and CVE‑2025‑9377.

    2000080
    3 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_c72.0--
OStp-linkarcher_c7_firmware---
HWtp-linktl-wr841nv9--
OStp-linktl-wr841n_firmware---
HWtp-linktl-wr841nd9--
OStp-linktl-wr841nd_firmware---

Explore more