Junglewise Threat Intelligence

CVE-2026-18330: TP-Link Archer AX55 hard-coded RSA key in web login

CVE-2026-18330 · Severity: info · CVSS 6.1 · Published 2026-09-03

Technologies: TP-Link Archer AX55. Vendors: TP-Link.

Executive brief

TP-Link Archer AX55 v4 routers contain a shared hard-coded RSA private key in their web login module. An attacker on the local network (LAN) who captures an HTTP login session can use this known key to decrypt the administrator password. Combined with weak session encryption, this allows attackers to compromise administrator credentials and take full control of the router.

Technical details

A hard-coded cryptographic key vulnerability exists in the web authentication module of TP-Link Archer AX55 v4. The vulnerability stems from the use of a shared RSA-1024 private key embedded in the firmware that is used for password encryption during HTTP login sessions. An attacker on the local network can passively capture HTTP login traffic, extract the RSA-encrypted password, and decrypt it using the known private key. The impact is further amplified by weak AES session key generation, reducing the computational effort required to compromise session confidentiality. Attack requires network adjacency (LAN access) and packet capture capability, but no authentication or user interaction. Successful exploitation discloses the administrator password and enables full compromise of device administration. The fix is available in firmware version 1.2.1 Build 20260527 or later.

Affected products

  • TP-Link Archer AX55 v4 prior to 1.2.1 Build 20260527

Timeline

  • 2026-09-03: disclosed

References

Related threats