CVE-2026-18330

Published Sep 3, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-18330 describes a hard-coded cryptographic key vulnerability found in the web module of the TP-Link Archer AX55 v4 router. This flaw allows a local area network (LAN) attacker who intercepts an HTTP login session to utilize a known shared RSA private key to decrypt the administrator password. The presence of a weakened AES session key further simplifies the process of compromising session confidentiality, potentially leading to the disclosure of the administrator password and a breach of session privacy.

Description
A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session confidentiality. Successful exploitation may disclose the administrator password captured from an HTTP login session and compromise session confidentiality.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.1
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

Weaknesses

f23511db-6c3e-4e32-a477-6aa17d310630
CWE-321

Social media

Hype score
Not currently trending