Cryptographic Key Vulnerability in TP-Link Archer AX55
CVE-2026-18330

6.1MEDIUM

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-18330?

A hard-coded cryptographic key vulnerability exists in the web module of the TP-Link Archer AX55 v4. Attackers on the local network can exploit this flaw by capturing an HTTP login session. Using a known shared RSA private key, they can decrypt the administrator password. The vulnerability is exacerbated by a weakened AES session key, which makes it easier to compromise session confidentiality. This could lead to unauthorized access and potential administrative control over the device.

Affected Version(s)

Archer AX55 v4 0 < 1.2.1 Build 20260527

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tianchang Yang and Syed Rafiul Hussain (SyNSec Lab, Penn State University)
.