Cyber Security News

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices.

The flaws, tracked as CVE-2026-18167 and CVE-2026-18330, affect the EasyMesh and web login modules in Archer AX55 hardware version V4.

TP-Link released firmware version 1.2.1 Build 20260527 to address both issues. The company published its advisory on September 3, 2026.

The most serious issue, CVE-2026-18167, is a stack-based buffer overflow in the router’s EasyMesh component. It has a CVSS v4 score of 7.7 and is rated High severity.

EasyMesh connects compatible networking devices into a single mesh Wi-Fi network. According to TP-Link, the vulnerability becomes exploitable when Mesh mode is enabled on the Archer AX55 v4.

An attacker connected to the target’s local network could send specially crafted input to the EasyMesh service, known as the easymesh daemon. The malicious input could force the service to crash.

In some cases, the flaw could also allow the attacker to run code on the router. Remote code execution on a router is particularly dangerous because the device sits between local systems and the internet.

Attackers who compromise a router may attempt to monitor network traffic, alter DNS settings, redirect users to malicious websites, scan connected devices, or use the router as a foothold to attack the wider network.

TP-Link said successful exploitation could have a high impact on the confidentiality, integrity, and availability of the affected router. However, the attack requires local network access, and Mesh mode must be enabled.

The second vulnerability, CVE-2026-18330, affects the Archer AX55 v4 web login module. The flaw is caused by a hardcoded shared RSA-1024 private key embedded in the product.

A local attacker who captures an HTTP-based administrator login session could use the known private key to decrypt the administrator password. TP-Link also noted that a weak AES session key reduces the effort required to compromise the login session’s confidentiality.

The issue received a CVSS v4 score of 6.1 and is rated Medium severity. Although it does not directly provide code execution, stolen router administrator credentials could give an attacker control over key configuration settings.

The weakness highlights the risks of using HTTP for administrative access. Unencrypted HTTP sessions can expose sensitive login data to attackers on the same network, especially on insecure or shared Wi-Fi networks.

The vulnerabilities affect TP-Link Archer AX55 routers with hardware version V4. The fixed firmware version is 1.2.1 Build 20260527. TP-Link strongly recommends that owners update their devices as soon as possible through the official Archer AX55 V4 firmware download page.

Users should also turn off Mesh mode when not needed, avoid managing the router over HTTP, use a strong, unique administrator password, and ensure that router management access is not exposed to untrusted networks.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

5 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

9 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

15 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

21 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

31 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago