You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-9377
About this tag
CVE-2025-9377 is an authenticated OS command injection and remote command execution vulnerability affecting TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 devices. It has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. This flaw poses significant risk to enterprise networks when consumer or small-office routers remain unpatched. Discussions on WindowsForum.com highlight the urgency of mitigation, as CISA's Binding Operational Directive mandates federal agencies to address such vulnerabilities promptly. IT teams are advised to prioritize patching these TP-Link router models to prevent remote compromise.
CISA’s KEV catalog grew again this week with the addition of two high‑risk router flaws tied to active exploitation, underscoring an uncomfortable reality for IT teams: inexpensive consumer and small‑office routers remain a prime target for adversaries and can pose outsized risk to enterprise...