Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > TP-Link Patches Archer AX55 Flaws Enabling Code Execution and Password Theft
TP-Link Patches Archer AX55 Flaws Enabling Code Execution and Password Theft
Read Time:3 Minute, 46 Second

TP-Link has released firmware for two vulnerabilities in the Archer AX55 v4 router that could allow a nearby attacker to disrupt the device, recover administrator credentials or potentially execute code. The issues affect the EasyMesh service and the web-based login process, making the update particularly important for homes and small offices where untrusted devices share local network access.

The flaws are tracked as CVE-2026-18167 and CVE-2026-18330. Both apply specifically to Archer AX55 hardware version V4. TP-Link addressed them in firmware version 1.2.1 Build 20260527 and has advised owners to update through its official support channel.

EasyMesh overflow creates a path to code execution

CVE-2026-18167 is a stack-based buffer overflow in the router’s EasyMesh component. It carries a CVSS v4 score of 7.7 and a High severity rating. EasyMesh is designed to combine compatible networking devices into one mesh Wi-Fi environment, but the affected service can mishandle specially crafted input.

An attacker connected to the same local network could send malicious data to the easymesh daemon when Mesh mode is enabled. At minimum, exploitation can crash the service and interrupt mesh functions. Under some conditions, the memory corruption may let the attacker execute code on the router.

Control of a router is strategically valuable because all local devices rely on it to reach the internet. A successful intruder may be able to alter DNS settings, redirect users to fraudulent sites, inspect traffic that lacks end-to-end encryption, scan other systems or use the device as a foothold for further attacks. TP-Link assessed potential effects across confidentiality, integrity and availability.

The prerequisites limit, but do not remove, the danger. The attacker needs local network access, and Mesh mode must be active. In a household that might mean a compromised laptop, smart device or guest with Wi-Fi access. In a small office, one infected endpoint could provide exactly the position required to attack the router.

Shared cryptographic key weakens administrator logins

CVE-2026-18330 affects the Archer AX55 v4 web login module and is rated Medium with a CVSS v4 score of 6.1. The product contains a hardcoded, shared 1024-bit RSA private key. If a local attacker captures an administrator login conducted over HTTP, that known key can be used to decrypt the password. TP-Link also identified a weak AES session key that further reduces the confidentiality of the exchange.

This weakness does not independently provide code execution, but a recovered administrator password can unlock sensitive configuration. An attacker with management access could change name servers, expose services, weaken wireless settings or lock the legitimate owner out. Reused passwords would create additional risk on unrelated accounts.

The finding is also a reminder that an administrative page should not be considered safe merely because it is available only on the local network. Shared Wi-Fi, infected endpoints and malicious insiders can all observe local traffic. Plain HTTP provides no transport encryption and should not be used for router management when a protected alternative is available.

How Archer AX55 v4 owners should respond

  • Confirm the hardware label identifies the router as Archer AX55 version V4; firmware for another hardware revision may not be compatible.
  • Install version 1.2.1 Build 20260527 or a newer approved release from TP-Link’s official support page.
  • After installation, verify the reported firmware version and confirm that normal routing and wireless functions operate correctly.
  • Disable Mesh mode if it is not needed, and keep guest or untrusted devices separated from management interfaces.
  • Avoid HTTP administration, use a unique router password and change it if an unencrypted login may have been observed.

Router patching deserves endpoint-level urgency

Routers often run continuously for years and receive less attention than phones or computers, despite occupying a privileged position in the network. Automatic update settings should be reviewed rather than assumed, especially because rollout behavior can vary by region and internet provider.

Organizations managing several affected devices should inventory hardware revisions, record the fixed version and look for unexplained configuration changes or DNS entries. If compromise is suspected, a password change alone may be insufficient; administrators should preserve relevant logs, reset the device, apply trusted firmware and rebuild the configuration from known-good settings.

No active exploitation was described in the disclosure, and both vulnerabilities require local access. Prompt patching nevertheless removes two useful paths that malware on an already-compromised endpoint could use to gain deeper and more durable control of the network.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on TP-Link Patches Archer AX55 Flaws Enabling Code Execution and Password Theft, use the discussion on Forum.

>> forum community

Comments

Leave a Reply