TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices.
The flaws, tracked as CVE-2026-18167 and CVE-2026-18330, affect the EasyMesh and web login modules in Archer AX55 hardware version V4.
TP-Link released firmware version 1.2.1 Build 20260527 to address both issues. The company published its advisory on September 3, 2026.
The most serious issue, CVE-2026-18167, is a stack-based buffer overflow in the router’s EasyMesh component. It has a CVSS v4 score of 7.7 and is rated High severity.
EasyMesh connects compatible networking devices into a single mesh Wi-Fi network. According to TP-Link, the vulnerability becomes exploitable when Mesh mode is enabled on the Archer AX55 v4.
Multiple TP-Link Archer Vulnerabilities
An attacker connected to the target’s local network could send specially crafted input to the EasyMesh service, known as the easymesh daemon. The malicious input could force the service to crash.
In some cases, the flaw could also allow the attacker to run code on the router. Remote code execution on a router is particularly dangerous because the device sits between local systems and the internet.
Attackers who compromise a router may attempt to monitor network traffic, alter DNS settings, redirect users to malicious websites, scan connected devices, or use the router as a foothold to attack the wider network.
TP-Link said successful exploitation could have a high impact on the confidentiality, integrity, and availability of the affected router. However, the attack requires local network access, and Mesh mode must be enabled.
The second vulnerability, CVE-2026-18330, affects the Archer AX55 v4 web login module. The flaw is caused by a hardcoded shared RSA-1024 private key embedded in the product.
A local attacker who captures an HTTP-based administrator login session could use the known private key to decrypt the administrator password. TP-Link also noted that a weak AES session key reduces the effort required to compromise the login session’s confidentiality.
The issue received a CVSS v4 score of 6.1 and is rated Medium severity. Although it does not directly provide code execution, stolen router administrator credentials could give an attacker control over key configuration settings.
The weakness highlights the risks of using HTTP for administrative access. Unencrypted HTTP sessions can expose sensitive login data to attackers on the same network, especially on insecure or shared Wi-Fi networks.
The vulnerabilities affect TP-Link Archer AX55 routers with hardware version V4. The fixed firmware version is 1.2.1 Build 20260527. TP-Link strongly recommends that owners update their devices as soon as possible through the official Archer AX55 V4 firmware download page.
Users should also turn off Mesh mode when not needed, avoid managing the router over HTTP, use a strong, unique administrator password, and ensure that router management access is not exposed to untrusted networks.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code appeared first on Cyber Security News.
