Impact
The vulnerability arises from a hard‑coded RSA‑1024 private key embedded in the web module of TP‑Link Archer AX55 v4. A local network attacker who captures an unencrypted HTTP login session can use this known private key to decrypt the administrator password, and a weakened AES session key further lowers the effort required to compromise session confidentiality. Successful exploitation results in the disclosure of the administrator password and the ability to read or impersonate traffic to the router’s management interface.
Affected Systems
TP‑Link Systems Inc. Archer AX55 v4 routers are affected. No other variants or versions are listed in the supplied data.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the supplied metrics. The issue is not listed in CISA’s KEV catalog, implying no confirmed widespread exploitation. The likely attack vector is a local network attacker who can intercept the unencrypted HTTP session; the exploit requires only network proximity and the ability to capture traffic, without requiring remote code execution or privileged user access. Once the administrator’s password is revealed, the attacker can take full control of the router.
OpenCVE Enrichment