Security Advisory: Multiple Vulnerabilities in TP-Link Archer AX55 (CVE-2026-18167 & CVE-2026-18330)
Description of Vulnerabilities and Impacts:
TP-Link has identified two vulnerabilities in TP-Link Archer AX55 v4 affecting the EasyMesh and web modules.
CVE-2026-18167: Stack-based buffer overflow
A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device.
Successful exploitation may cause the EasyMesh daemon to crash and may potentially allow remote code execution when Mesh mode is enabled. This may result in high impact to the confidentiality, integrity, and availability of the affected device.
CVSS v4.0 Score: 7.7/ High
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVE-2026-18330: Hardcoded Shared RSA-1024 Private Key in Web Login
A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session confidentiality.
Successful exploitation may disclose the administrator password captured from an HTTP login session and compromise session confidentiality.
CVSS v4.0 Score: 6.1/ Medium
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Affected Products/Versions and Fixes:
|
Affected Product |
Hardware Version |
Fixed Version |
|
Archer AX55 |
V4 |
1.2.1 Build 20260527 |
Recommendations:
We strongly recommend that users with affected devices take the following actions:
- Follow the instructions to update to the latest firmware version to fix the vulnerabilities:
US: Download for Archer AX55 | TP-Link
Disclaimer:
This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.
Looking For More
Is this faq useful?
Your feedback helps improve this site.
TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.