TP-Link disclosed two vulnerabilities in the Archer AX55 v4 router on September 3, 2026. One flaw can crash the mesh service and may allow remote code execution. The other exposes the admin password to a local attacker. Both affect the popular Wi-Fi 6 home router.
- Product: TP-Link Systems Inc. Archer AX55 v4
- Vulnerabilities: 2 flaws (CVE-2026-18167, CVE-2026-18330)
- Highest severity: 7.7 (High · CVSSv4)
- Worst impact: Stack-based buffer overflow in TP-Link
- Status: No confirmed exploitation yet; patches available
- Action: Update to 1.2.1 Build 20260527 now
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-18167 | 7.7 | Stack-based buffer overflow in TP-Link | 1.2.1 Build 20260527 | Not exploited |
| CVE-2026-18330 | 6.1 | Hardcoded Shared RSA-1024 Private Key in TP-Link | 1.2.1 Build 20260527 | Not exploited |
Why the TP-Link Archer AX55 vulnerability matters
The Archer AX55 is a widely deployed Wi-Fi 6 router in homes and small offices. As a result, any flaw in its core services reaches a large user base. TP-Link’s advisory confirms two issues in the EasyMesh and web modules. Together, they threaten device control and credential security.
The more serious bug is a stack-based buffer overflow. According to TP-Link, “when Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device.” Therefore, an attacker on the same network could seize control of the router.
How the attacks work
CVE-2026-18167: EasyMesh buffer overflow
This vulnerability lives in the EasyMesh module. When Mesh mode is on, a LAN attacker sends crafted input to the easymesh daemon. That input overruns a stack buffer. The daemon then crashes, and code execution may follow. TP-Link warns this “may result in high impact to the confidentiality, integrity, and availability of the affected device.” It carries a CVSS v4.0 score of 7.7, rated High.
CVE-2026-18330: Hardcoded RSA private key
The second flaw sits in the web login module. The router ships a shared, hardcoded RSA-1024 private key. Consequently, a LAN attacker who captures an HTTP login session can decrypt the admin password. A weakened AES session key makes the job easier. This issue scores 6.1, rated Medium.
Exploitation status
No public proof-of-concept exists at this time. Likewise, no exploitation in the wild has been confirmed. Both bugs require local network access, which limits remote risk. Still, guests, malware, or compromised devices could supply that access. So patching remains urgent.
Affected versions
The vulnerabilities affect the TP-Link Archer AX55 V4 on hardware version 1.2.1 and earlier builds. TP-Link fixed both flaws in build 20260527. Older firmware stays exposed until you update.
Patch and mitigation steps
Update the router firmware right away. TP-Link recommends installing build 20260527 or later. You can find the download on the vendor’s official Archer AX55 support page. After updating, change the admin password and use HTTPS where possible. If you do not need mesh networking, disable Mesh mode to reduce the buffer overflow risk.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!