logo

TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft

ID: cac948bb-188f-56d5-b07b-71dbad6cdc20

STIX ID: report--cac948bb-188f-56d5-b07b-71dbad6cdc20

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-09-04

Date Updated: 2026-09-11

Author: Divya

...
...

TP-Link published an advisory for the Archer AX55 (V4) fixing two vulnerabilities in firmware 1.2.1 Build 20260527: CVE-2026-18167 (stack-based buffer overflow in EasyMesh that can crash the easymesh daemon and potentially enable remote code execution when Mesh mode is enabled) and CVE-2026-18330 (a hardcoded RSA-1024 private key in the web login module that can let a local attacker decrypt admin passwords). The advisory urges firmware updates and recommends disabling HTTP admin access, using HTTPS, restricting management to trusted devices, and monitoring connected clients.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.