THE TP-Link Archer AX55 v4 has two critical vulnerabilities disclosed on September 3, 2026. These include CVE-2026-18167 (a stack-based buffer overflow that could allow remote code execution) and CVE-2026-18330 (a hardcoded RSA-1024 private key exposure allowing local attackers to decrypt admin passwords). The vulnerabilities, with severity scores of 7.7 and 6.1 respectively, require local network access to exploit but pose significant risks to device security and control. Patches are available in firmware version 1.2.1 Build 20260527, and immediate updates are advised to mitigate threats.
TP-Link Archer AX55 Flaws Expose Routers to Code Execution
CyberSIXT Evidence Panel
Article by CyberSIXT