{"id":"CVE-2026-18330","title":"A hard-coded\ncryptographic key vulnerability exists in the web module of TP-Link Archer\nAX55 v4","summary":"A hard-coded\ncryptographic key vulnerability exists in the web module of TP-Link Archer\nAX55 v4. A LAN attacker who captures an HTTP login session may use the known\nshared RSA private key to decrypt the administrator password; the\nweaken…","severity":"none","cwe":["CWE-321"],"published":"2026-09-03","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:15:18.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18330","references":[{"url":"https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5279/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd"],"epss":0.00232,"epssPercentile":0.14322,"ingestedAt":"2026-09-08T20:10:03.161Z","slug":"CVE-2026-18330","body":"## Overview\n\nA hard-coded\ncryptographic key vulnerability exists in the web module of TP-Link Archer\nAX55 v4. A LAN attacker who captures an HTTP login session may use the known\nshared RSA private key to decrypt the administrator password; the\nweakened AES session key further reduces the effort required to\ncompromise session confidentiality.\n\n\n\n\n\nSuccessful\nexploitation may disclose the administrator password captured from an HTTP\nlogin session and compromise session confidentiality.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}