Stack-based Buffer Overflow in TP-Link Archer AX55 EasyMesh Module
CVE-2026-18167

7.7HIGH

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-18167?

A stack-based buffer overflow vulnerability has been identified in the EasyMesh module of the TP-Link Archer AX55 version 4. When Mesh mode is active, an attacker on the local network could exploit this flaw by sending specially crafted input, potentially leading to the crash of the EasyMesh daemon and enabling unauthorized remote code execution on the device. This poses serious risks to the device's confidentiality, integrity, and availability, emphasizing the need for immediate user awareness and prompt application of security updates.

Affected Version(s)

Archer AX55 v4 0 < 1.2.1 Build 20260527

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tianchang Yang and Syed Rafiul Hussain (SyNSec Lab, Penn State University)
.