{"id":"CVE-2026-18167","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-18167","summary":"A\nstack-based buffer overflow vulnerability exists in the EasyMesh module of\nTP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit\ncrafted input that causes the…","details":"A\nstack-based buffer overflow vulnerability exists in the EasyMesh module of\nTP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit\ncrafted input that causes the easymesh daemon to crash and may potentially\nachieve remote code execution on the device.\n\n\n\n\n\nSuccessful\nexploitation may cause the EasyMesh daemon to crash and may potentially allow\nremote code execution when Mesh mode is enabled. This\nmay result in high impact to the confidentiality, integrity, and availability\nof the affected device.","published":"2026-09-03T23:17:19.260","modified":"2026-09-03T23:17:19.260","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/us/support/faq/5279/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T23:17:19.260"}}