CVE-2026-18167
Received Received - Intake

Stack-Based Buffer Overflow in TP-Link Archer AX55

Vulnerability report for CVE-2026-18167, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: TPLink

Description

A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. Successful exploitation may cause the EasyMesh daemon to crash and may potentially allow remote code execution when Mesh mode is enabled. This may result in high impact to the confidentiality, integrity, and availability of the affected device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tp-link archer_ax55 v4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stack-based buffer overflow in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker can send crafted input to crash the easymesh daemon and potentially execute remote code on the device.

Impact Analysis

Exploitation may crash the EasyMesh daemon and allow remote code execution, leading to high impact on the device's confidentiality, integrity, and availability. An attacker on the same network could gain control of the device.

Compliance Impact

This vulnerability may lead to remote code execution on the device, potentially compromising confidentiality, integrity, and availability. Such breaches could violate data protection requirements under GDPR or HIPAA if sensitive data is exposed or altered.

Mitigation Strategies

Disable Mesh mode on the TP-Link Archer AX55 v4 to prevent potential exploitation. Ensure the device firmware is updated to the latest version if a patch is available. Monitor network traffic for unusual activity related to the EasyMesh daemon.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18167. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart