Junglewise Threat Intelligence

CVE-2026-18167: TP-Link Archer AX55 stack-based buffer overflow in EasyMesh

CVE-2026-18167 · Severity: info · CVSS 7.7 · Published 2026-09-03

Technologies: TP-Link Archer AX55. Vendors: TP-Link.

Executive brief

The TP-Link Archer AX55 router's EasyMesh module (used to extend and manage mesh Wi-Fi networks) contains a buffer overflow flaw that can be exploited by attackers on the local network. An attacker can send specially crafted data to crash the mesh service or potentially gain full control of the device when mesh mode is enabled, compromising its security, data handling, and availability.

Technical details

A stack-based buffer overflow exists in the EasyMesh daemon of TP-Link Archer AX55 v4 when Mesh mode is enabled. The vulnerability allows a local network (LAN) attacker to submit crafted input that triggers the overflow, causing the easymesh daemon to crash. An attacker with network access to the device can exploit this to achieve remote code execution with the privileges of the daemon process. The vulnerability requires no authentication and the affected versions are Archer AX55 V4 prior to firmware 1.2.1 Build 20260527, which contains the fix. The attack vector is adjacent network access.

Affected products

  • TP-Link Archer AX55 v4 (prior to 1.2.1 Build 20260527)

Timeline

  • 2026-09-03: disclosed

References

Related threats