AI description
CVE-2026-18167 describes a stack-based buffer overflow vulnerability found within the EasyMesh module of the TP-Link Archer AX55 v4 router. This flaw can be exploited when the Mesh mode is active on the device. A local area network (LAN) attacker can leverage this vulnerability by submitting specially crafted input. This malicious input has the potential to cause the easymesh daemon to crash, and in some scenarios, it may also enable remote code execution on the affected device.
- Description
- A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. Successful exploitation may cause the EasyMesh daemon to crash and may potentially allow remote code execution when Mesh mode is enabled. This may result in high impact to the confidentiality, integrity, and availability of the affected device.
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 7.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- f23511db-6c3e-4e32-a477-6aa17d310630
- CWE-121
- Hype score
- Not currently trending
⚠️ TP-Link Archer AX55 (V4) has 2 flaws — CVE-2026-18167 (RCE risk) & CVE-2026-18330 (admin password theft). Update to firmware 1.2.1 Build 20260527 NOW. 🔗 https://t.co/SRNUGBhVVZ #CyberSecurity #InfoSec #TPLink #CVE2026 #RouterSecurity #PatchNow https://t.co/Cbrqmy
@Xpert4Cyber
7 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Vulnerabilidades en TP-Link Archer permiten ejecución remota de código TP-Link ha revelado dos vulnerabilidades de seguridad ( CVE-2026-18167 y CVE-2026-18330 ) en su router Archer AX55 v4 https://t.co/PghxPA0tEl
@elhackernet
6 Sept 2026
5164 Impressions
18 Retweets
54 Likes
10 Bookmarks
0 Replies
1 Quote
🚨 TP-Link Archer AX55 users: check your firmware now. Two vulnerabilities affect Archer AX55 V4: 🔴 CVE-2026-18167 — EasyMesh stack-based buffer overflow → potential RCE 🔴 CVE-2026-18330 — hardcoded RSA private key → admin credential theft ⚠️ Update to 1.2.1
@thecybersecguru
5 Sept 2026
121 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 TP-Link Archer AX55 V4 routerlarda RCE riski! Routerdaki CVE-2026-18167 adlı EasyMesh açığı, aynı yerel ağdaki saldırganların özel hazırlanmış veriler göndererek cihaz üzerinde kod çalıştırmasına yol açabiliyor. CVE-2026-18330 ise HTTP üzerinden yapıl
@ridvanyagli
4 Sept 2026
207 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
🚨 HIGH: CVE-2026-18167 (CVSS 7.7) is a stack-based buffer overflow in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker can send crafted input to the EasyMesh daemon, potentially causing a crash or achieving remote code execution on the
@ThreatWire_
4 Sept 2026
208 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
A TP-Link Archer AX55 vulnerability (CVE-2026-18167) risks remote code execution via EasyMesh buffer overflow. Update to build 20260527 now. #TPLink #ArcherAX55 #RouterSecurity #CVE #BufferOverflow #NetworkSecurity #Infosec https://t.co/OVKlzZLxPq https://t.co/t8VInkuSll
@Daily_CyberSec
4 Sept 2026
372 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes