Click to skip the navigation bar

Security Advisory: Multiple Vulnerabilities in TP-Link Archer AX55 (CVE-2026-18167 & CVE-2026-18330)

Security Advisory
Last updated: September 3, 2026

Description of Vulnerabilities and Impacts:

TP-Link has identified two vulnerabilities in TP-Link Archer AX55 v4 affecting the EasyMesh and web modules.

CVE-2026-18167: Stack-based buffer overflow

A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device.

Successful exploitation may cause the EasyMesh daemon to crash and may potentially allow remote code execution when Mesh mode is enabled. This may result in high impact to the confidentiality, integrity, and availability of the affected device.

CVSS v4.0 Score: 7.7/ High

CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

CVE-2026-18330: Hardcoded Shared RSA-1024 Private Key in Web Login

A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session confidentiality.

Successful exploitation may disclose the administrator password captured from an HTTP login session and compromise session confidentiality.

CVSS v4.0 Score: 6.1/ Medium

CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products/Versions and Fixes:

Affected Product

Hardware Version

Fixed Version

Archer AX55

V4

1.2.1 Build 20260527

Recommendations:

We strongly recommend that users with affected devices take the following actions:

  1. Follow the instructions to update to the latest firmware version to fix the vulnerabilities:

US: Download for Archer AX55 | TP-Link

Disclaimer:

This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.

Related FAQs

Looking For More

Is this faq useful?

Your feedback helps improve this site.

Community

TP-Link Community

Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.

Visit the Community >