← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 4, 2026 · 12:16via Cyber Security News

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

Brief

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices.

The flaws, tracked as CVE-2026-18167 and CVE-2026-18330, affect the EasyMesh and web login modules in Archer AX55 hardware version V4.

TP-Link released firmware version 1.

  • 1 Build 20260527 to address both issues. The company published its advisory on September 3, 2026.

The most serious issue, CVE-2026-18167, is a stack-based buffer overflow in the router’s EasyMesh component. It has a CVSS v4 score of 7. 7 and is rated High severity.

EasyMesh connects compatible networking devices into a single mesh Wi-Fi network. According to TP-Link, the vulnerability becomes exploitable when Mesh mode is enabled on the Archer AX55 v4.

Read more on Cyber Security News