Two TP-Link Archer Router Vulnerabilities Enable Local Code Execution and Credential Theft
TP-Link has released firmware updates to address two critical vulnerabilities in its Archer AX55 v4 router, which could allow local attackers to execute remote code and steal credentials.

TP-Link has disclosed two significant security vulnerabilities affecting its Archer AX55 v4 router, potentially enabling local attackers to crash services, steal administrator credentials, and even execute remote code. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the EasyMesh and web login modules respectively. TP-Link has responded by releasing firmware version 1.2.1 Build 20260527 to patch these issues, with an advisory published on September 3, 2026.
The more severe of the two, CVE-2026-18167, is a stack-based buffer overflow vulnerability within the router's EasyMesh component. This flaw, which carries a CVSS v4 score of 7.7 and is classified as High severity, becomes exploitable when Mesh mode is enabled on the Archer AX55 v4. An attacker with local network access could send specially crafted input to the EasyMesh daemon, leading to a service crash and, in some scenarios, enabling remote code execution. Compromising a router can have severe consequences, including network traffic monitoring, DNS manipulation, redirection to malicious sites, and serving as a pivot point for further network attacks.
TP-Link noted that successful exploitation of CVE-2026-18167 could significantly impact the confidentiality, integrity, and availability of the affected router. However, the attack vector is limited to local network access, and the Mesh mode must be active for exploitation to occur. The potential for remote code execution on a device that acts as a gateway between a local network and the internet makes this vulnerability particularly concerning for home and small business users.
The second vulnerability, CVE-2026-18330, resides in the Archer AX55 v4's web login module. It stems from a hardcoded shared RSA-1024 private key embedded within the product. This weakness allows a local attacker who intercepts an HTTP-based administrator login session to decrypt the administrator's password using the known private key. Compounding this issue, a weak AES session key further reduces the effort required to compromise the session's confidentiality. Rated Medium severity with a CVSS v4 score of 6.1, this vulnerability does not directly lead to code execution but provides attackers with stolen credentials, granting them control over critical router configurations.
The reliance on unencrypted HTTP for administrative access, as highlighted by CVE-2026-18330, poses a significant risk, especially on less secure or public Wi-Fi networks. Sensitive login data can be easily exposed to eavesdroppers on the same network. The combination of these vulnerabilities underscores the importance of maintaining secure network devices and practicing good security hygiene.
TP-Link strongly advises users of the Archer AX55 v4 router to update their devices to the latest firmware version, 1.2.1 Build 20260527, as soon as possible. Beyond firmware updates, users are encouraged to disable Mesh mode when not actively in use, avoid managing the router over HTTP, implement strong and unique administrator passwords, and ensure that router management interfaces are not exposed to untrusted networks. These proactive measures can significantly mitigate the risk posed by these and other potential vulnerabilities.