cryptographic key vulnerability exists in the web module of TP-Link Archer
AX55 v4. A LAN attacker who captures an HTTP login session may use the known
shared RSA private key to decrypt the administrator password; the
weakened AES session key further reduces the effort required to
compromise session confidentiality.
Successful
exploitation may disclose the administrator password captured from an HTTP
login session and compromise session confidentiality.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link archer Ax55 V4 |
|
| Vendors & Products |
Tp-link
Tp-link archer Ax55 V4 |
Thu, 03 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session confidentiality. Successful exploitation may disclose the administrator password captured from an HTTP login session and compromise session confidentiality. | |
| Title | Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4 | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-09-04T18:25:58.339Z
Reserved: 2026-07-29T20:03:53.524Z
Link: CVE-2026-18330
Updated: 2026-09-04T17:39:53.006Z
Status : Received
Published: 2026-09-03T23:17:19.400
Modified: 2026-09-04T19:17:24.507
Link: CVE-2026-18330
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:21:52Z