Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18330— Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4

Quick assessment

Affected
TP-Link Systems Inc. Archer AX55 v4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TP-Link Archer AX55 v4 的 Web 模块中存在硬编码加密密钥漏洞。局域网(LAN)攻击者若捕获了 HTTP 登录会话,可利用已知的共享 RSA 私钥解密管理员密码;而强度较弱的 AES 会话密钥进一步降低了破坏会话机密性所需的努力程度。 成功利用该漏洞可能泄露从 HTTP 登录会话中捕获的管理员密码,并破坏会话的机密性。

CVSS 6.1 · Medium

Possible ATT&CK Techniques 1 AI

T1567 · Exfiltration Over Web Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18330

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4
Source: CVE Program / CVE List V5
Vulnerability Description
A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session confidentiality. Successful exploitation may disclose the administrator password captured from an HTTP login session and compromise session confidentiality.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的密码学密钥
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. Archer AX55 v4 0 ~ 1.2.1 Build 20260527 -

II. Public POCs for CVE-2026-18330

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18330

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18330 (1)

Vendor Pages for CVE-2026-18330 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18330

No comments yet


Leave a comment