AI description
CVE-2026-18330 describes a hard-coded cryptographic key vulnerability found in the web module of the TP-Link Archer AX55 v4 router. This flaw allows a local area network (LAN) attacker who intercepts an HTTP login session to utilize a known shared RSA private key to decrypt the administrator password. The presence of a weakened AES session key further simplifies the process of compromising session confidentiality, potentially leading to the disclosure of the administrator password and a breach of session privacy.
- Description
- A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session confidentiality. Successful exploitation may disclose the administrator password captured from an HTTP login session and compromise session confidentiality.
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 6.1
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
- f23511db-6c3e-4e32-a477-6aa17d310630
- CWE-321
- Hype score
- Not currently trending
⚠️ TP-Link Archer AX55 (V4) has 2 flaws — CVE-2026-18167 (RCE risk) & CVE-2026-18330 (admin password theft). Update to firmware 1.2.1 Build 20260527 NOW. 🔗 https://t.co/SRNUGBhVVZ #CyberSecurity #InfoSec #TPLink #CVE2026 #RouterSecurity #PatchNow https://t.co/Cbrqmy
@Xpert4Cyber
7 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Vulnerabilidades en TP-Link Archer permiten ejecución remota de código TP-Link ha revelado dos vulnerabilidades de seguridad ( CVE-2026-18167 y CVE-2026-18330 ) en su router Archer AX55 v4 https://t.co/PghxPA0tEl
@elhackernet
6 Sept 2026
5164 Impressions
18 Retweets
54 Likes
10 Bookmarks
0 Replies
1 Quote
🚨 TP-Link Archer AX55 users: check your firmware now. Two vulnerabilities affect Archer AX55 V4: 🔴 CVE-2026-18167 — EasyMesh stack-based buffer overflow → potential RCE 🔴 CVE-2026-18330 — hardcoded RSA private key → admin credential theft ⚠️ Update to 1.2.1
@thecybersecguru
5 Sept 2026
121 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 TP-Link Archer AX55 V4 routerlarda RCE riski! Routerdaki CVE-2026-18167 adlı EasyMesh açığı, aynı yerel ağdaki saldırganların özel hazırlanmış veriler göndererek cihaz üzerinde kod çalıştırmasına yol açabiliyor. CVE-2026-18330 ise HTTP üzerinden yapıl
@ridvanyagli
4 Sept 2026
207 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes