Critical TP-Link Archer Flaws Let Attackers Run Remote Code
Key Takeaways TP-Link has addressed two critical vulnerabilities, CVE-2026-18167 and CVE-2026-18330, in its Archer AX55 v4 routers. The flaws could enable local network attackers to crash services,...
Key Takeaways
- TP-Link has addressed two critical vulnerabilities, CVE-2026-18167 and CVE-2026-18330, in its Archer AX55 v4 routers.
- The flaws could enable local network attackers to crash services, steal administrator credentials, and potentially execute remote code.
- The most severe vulnerability, a stack-based buffer overflow in the EasyMesh component, carries a CVSS v4 score of 7.7.
- A firmware update, version 1.2.1 Build 20260527, has been released to patch both issues.
- Immediate action is recommended for all affected Archer AX55 v4 users.
TP-Link Archer AX55 v4 Routers Hit by Critical Flaws
TP-Link has disclosed a pair of significant security vulnerabilities impacting its Archer AX55 v4 router models. These flaws could allow malicious actors on a local network to disrupt device services, compromise administrator credentials, and potentially achieve remote code execution on the affected hardware.
Table Of Content
The identified vulnerabilities are cataloged as CVE-2026-18167 and CVE-2026-18330. Both issues specifically target the EasyMesh and web login modules within the Archer AX55 hardware version V4. TP-Link released a firmware update, version 1.2.1 Build 20260527, to mitigate these risks, with an advisory published on September 3, 2026.
EasyMesh Vulnerability Poses Remote Code Execution Risk
The more severe of the two, CVE-2026-18167, is a stack-based buffer overflow found in the EasyMesh component of the router. This vulnerability has been assigned a CVSS v4 score of 7.7, categorizing it as High severity.
EasyMesh technology is designed to unify compatible networking devices into a single, cohesive Wi-Fi mesh network. According to TP-Link, this particular vulnerability becomes exploitable when the Mesh mode feature is active on the Archer AX55 v4 device.
An attacker with access to the local network could send specially crafted input to the easymesh daemon, the service responsible for EasyMesh functionality. This malicious input has the potential to force the service to crash. In certain scenarios, this flaw could also be leveraged to execute arbitrary code on the router.
Gaining remote code execution on a network router is particularly dangerous. As the gateway between internal systems and the internet, a compromised router can become a critical pivot point for attackers. Such a compromise could enable adversaries to monitor network traffic, alter DNS settings to redirect users to malicious sites, scan connected devices for further vulnerabilities, or establish a foothold for deeper network penetration.
TP-Link said that successful exploitation of this vulnerability could have a high impact on the confidentiality, integrity, and availability of the affected router. However, it requires local network access, and the Mesh mode must be enabled for the attack to succeed.
Hardcoded Key Exposes Admin Passwords
The second vulnerability, CVE-2026-18330, resides within the web login module of the Archer AX55 v4. This flaw stems from a hardcoded, shared RSA-1024 private key embedded within the product’s design.
A local attacker capable of intercepting an HTTP-based administrator login session could exploit this known private key to decrypt the administrator’s password. TP-Link further noted that a weak AES session key additionally reduces the effort required to compromise the confidentiality of the login session.
This issue received a CVSS v4 score of 6.1, classifying it as Medium severity. While it does not directly facilitate code execution, the theft of router administrator credentials grants an attacker significant control over critical configuration settings, posing a substantial security risk.
The presence of this weakness underscores the inherent dangers associated with using unencrypted HTTP for administrative access. HTTP sessions can expose sensitive login data to adversaries on the same network, a risk particularly amplified in insecure or shared Wi-Fi environments.
These vulnerabilities specifically affect TP-Link Archer AX55 routers with hardware version V4. The remediated firmware is version 1.2.1 Build 20260527. TP-Link strongly advises all owners to update their devices promptly via the official Archer AX55 V4 firmware download page.
What You Should Do
- Update Firmware Immediately: Download and install firmware version 1.2.1 Build 20260527 for your Archer AX55 v4 router from the official TP-Link support page.
- Disable EasyMesh When Not Needed: If you do not actively use the EasyMesh feature, disable it to reduce the attack surface.
- Avoid HTTP for Management: Always access your router’s administration interface using HTTPS to encrypt your connection and protect login credentials.
- Use Strong, Unique Passwords: Ensure your router’s administrator account uses a complex, unique password that is not reused elsewhere.
- Restrict Management Access: Configure your router to prevent management access from untrusted networks or the internet unless absolutely necessary, and if so, use strong access controls like VPNs.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.