Cryptographic Key Vulnerability in TP-Link Archer AX55
CVE-2026-18330
6.1MEDIUM
What is CVE-2026-18330?
A hard-coded cryptographic key vulnerability exists in the web module of the TP-Link Archer AX55 v4. Attackers on the local network can exploit this flaw by capturing an HTTP login session. Using a known shared RSA private key, they can decrypt the administrator password. The vulnerability is exacerbated by a weakened AES session key, which makes it easier to compromise session confidentiality. This could lead to unauthorized access and potential administrative control over the device.
Affected Version(s)
Archer AX55 v4 0 < 1.2.1 Build 20260527
References
CVSS V4
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tianchang Yang and Syed Rafiul Hussain (SyNSec Lab, Penn State University)
