ZeroHour

CVE-2026-18167

large

Stack Buffer Overflow in TP-Link Archer AX55 v4 EasyMesh Daemon

CVSS 4.0
7.7 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-18167 is a stack-based buffer overflow (CWE-121) in the EasyMesh module of the TP-Link Archer AX55 v4 router. When Mesh mode is enabled, an attacker positioned on the LAN (adjacent network, no credentials or user interaction required) can send crafted input to the easymesh daemon that overflows a stack buffer. Successful exploitation crashes the EasyMesh daemon and may potentially allow remote code execution on the device, with high impact to the confidentiality, integrity, and availability of the affected router. Only Archer AX55 v4 units with Mesh mode enabled are affected; units running in standard (non-mesh) mode are not exposed to this flaw. As of this writing there is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a low 0.3% probability of exploitation in the next 30 days.

What to do: Check whether your Archer AX55 v4 is running in Mesh/EasyMesh mode; if mesh operation is not required, disable it until a fix is available. Monitor TP-Link's security advisories and update to the fixed firmware once TP-Link publishes a patch (no fixed version is provided in the current data). Restrict LAN access to trusted devices in the meantime, since exploitation requires an adjacent network attacker.

Affected
TP-Link Archer AX55 v4 (EasyMesh module / easymesh daemon)v4 hardware with Mesh mode enabled; affected and fixed firmware versions not specified in the available data
Estimated exposure
largelikely hundreds of thousands of devices (top-selling consumer Wi-Fi 6 router model; the v4-with-Mesh-mode subset is smaller) — TP-Link is one of the highest-volume consumer router vendors and the Archer AX55 line has been a long-running budget Wi-Fi 6 bestseller, implying cumulative units in the hundreds of thousands to millions, narrowed to the v4 variant with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. Successful exploitation may cause the EasyMesh daemon to crash and may potentially allow remote code execution when Mesh mode is enabled. This may result in high impact to the confidentiality, integrity, and availability of the affected device.

Weakness
CWE-121
Vector
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.