Description
A
stack-based buffer overflow vulnerability exists in the EasyMesh module of
TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit
crafted input that causes the easymesh daemon to crash and may potentially
achieve remote code execution on the device.





Successful
exploitation may cause the EasyMesh daemon to crash and may potentially allow
remote code execution when Mesh mode is enabled. This
may result in high impact to the confidentiality, integrity, and availability
of the affected device.
Published: 2026-09-03
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow in the EasyMesh module of the TP‑Link Archer AX55 v4 router. When Mesh mode is enabled, a malicious actor with LAN-level access can send specially crafted data that overflows a buffer in the easymesh daemon, causing it to crash. In the worst case, the overflow may enable remote code execution on the device, allowing an attacker to compromise the router’s confidentiality, integrity, and availability. This flaw follows CWE‑121 and was assessed with a CVSS base score of 7.7.

Affected Systems

Affected devices are the TP‑Link Archer AX55 v4 routers. Firmware version v4 is the only version explicitly noted as vulnerable; newer firmware releases may have mitigated the issue, but the CVE only specifies v4.

Risk and Exploitability

The CVSS score indicates a high severity vulnerability; however, no EPSS data is presently available, so the estimated likelihood of exploitation is unknown. The flaw requires Mesh mode to be active and the attacker to be on the same local network, which typically confines exploitation to internal or compromised network environments. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Despite the absence of EPSS information, the potential for remote code execution warrants prompt action.

Generated by OpenCVE AI on September 3, 2026 at 23:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest version available from TP‑Link's official support site, which contains the fix for the EasyMesh buffer overflow.
  • If a firmware update is not immediately available or cannot be applied, disable Mesh mode to eliminate the attack surface until a patch is installed.
  • Ensure the router is isolated from untrusted LAN segments and enforce strong administrator credentials to reduce the risk of local compromise.

Generated by OpenCVE AI on September 3, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. Successful exploitation may cause the EasyMesh daemon to crash and may potentially allow remote code execution when Mesh mode is enabled. This may result in high impact to the confidentiality, integrity, and availability of the affected device.
Title Stack-based buffer overflow in TP-Link Archer AX55 v4
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-09-03T22:24:57.369Z

Reserved: 2026-07-28T20:48:04.039Z

Link: CVE-2026-18167

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T23:17:19.260

Modified: 2026-09-03T23:17:19.260

Link: CVE-2026-18167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T23:45:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow