---
id: CVE-2026-18167
title: |-
  A
  stack-based buffer overflow vulnerability exists in the EasyMesh module of
  TP-Link Archer AX55 v4
summary: |-
  A
  stack-based buffer overflow vulnerability exists in the EasyMesh module of
  TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit
  crafted input that causes the easymesh daemon to crash and may potentially
  achieve …
severity: none
cwe:
  - CWE-121
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:15:18.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18167'
references:
  - url: 'https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5279/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
epss: 0.0027
epssPercentile: 0.19431
ingestedAt: '2026-09-08T20:10:03.161Z'
---

## Overview

A
stack-based buffer overflow vulnerability exists in the EasyMesh module of
TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit
crafted input that causes the easymesh daemon to crash and may potentially
achieve remote code execution on the device.





Successful
exploitation may cause the EasyMesh daemon to crash and may potentially allow
remote code execution when Mesh mode is enabled. This
may result in high impact to the confidentiality, integrity, and availability
of the affected device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
