important · Wi-Fi — TP-Link
A LAN observer can recover the administrator password from an Archer AX55 v4 login session.
Affects
TP-Link Archer AX55 v4, a consumer Wi-Fi router running embedded firmware.
The observer must capture an actual HTTP login, then uses a shared RSA private key and weakened AES session key to decrypt the reusable password.
Detail and 2 sources
TP-Link has published a fix, but no public exploit implementation is established.