CVE-2026-18167: TP-Link Systems Inc Archer AX55 v4

High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. Successful exploitation may cause the EasyMesh daemon to crash and may potentially allow remote code execution when Mesh mode is enabled. This may result in high impact to the confidentiality, integrity, and availability of the affected device.

Affected products

  • TP-Link Systems Inc Archer AX55 v4: before 1.2.1 Build 20260527 (fixed in 1.2.1 Build 20260527)

Published 2026-09-03. Last modified 2026-09-08.