important · Wi-Fi
A LAN observer can recover an Archer AX55 administrator password from a captured login.
Affects
TP-Link Archer AX55 V4, an embedded Wi-Fi 6 home router.
Affected firmware combines a firmware-wide RSA-1024 private key with weakened AES session-key construction, allowing an observer of the HTTP management login to decrypt the password.
Detail and 3 sources
TP-Link fixed the affected Archer AX55 V4 firmware; no public researcher write-up or exploit was available by the cutoff.