TP-Link Archer AX55 v1

This image is for the Archer AX55 v1 only. Other revisions and similarly named models use different hardware and must not be flashed with it:

  • AX55 Pro v1: has 2.5 Gbit ports, so its ethernet hardware differs from the v1. It is not supported, and the AX55 v1 images are not meant for it. See AX55 Pro v1 below.
  • AX55 v2: different hardware, not supported by this image.
  • AX55 v4: different hardware, not supported by this image. See the forum thread.

The revision is printed on the label on the bottom of the router (the “Ver.” field). If it does not say 1.0, stop here.

Two switch variants are sold as “Archer AX55 v1”. Some units have a Realtek RTL8367S switch, which is supported. Others have an RTL8367S-VB, which current OpenWrt does not support yet. On an -VB unit OpenWrt boots with no working wired ports, and because Wi-Fi is off by default you cannot reach it at all. The unit is not bricked (the web recovery always works), but check your switch before you write anything to flash. How to check is described under Installation.

The TP-Link Archer AX55 v1 is a dual-band Wi-Fi 6 router (IPQ5018) with 5 gigabit ethernet ports and one USB 3.0 port. It is supported in OpenWrt snapshots since commit 8ac63a1c35.

 Archer AX55 (v1 and Pro v1 share this enclosure)

 Archer AX55 (v1 and Pro v1 share this enclosure)

Snapshot images are in targets/qualcommax/ipq50xx. There is no stable release with this device yet.

Image Use
...-tplink_archer-ax55-v1-initramfs-uImage.itb Boots from RAM over TFTP (serial install). Nothing is written to flash.
...-tplink_archer-ax55-v1-initramfs-factory.ubi The same RAM image as a UBI image, written from the stock firmware (serial-free install).
...-tplink_archer-ax55-v1-squashfs-sysupgrade.bin The permanent install and later upgrades, flashed from a running OpenWrt.
...-tplink_archer-ax55-v1-squashfs-factory.ubi Full UBI image of the permanent install.

SoC Qualcomm IPQ5018, 2 × Cortex-A53
Switch Realtek RTL8367S or RTL8367S-VB (see the warning above), connected to the SoC over a 2.5G HSGMII link
Flash two firmware slots, see Flash layout
Buttons Reset, WPS/Wi-Fi
LEDs power, LAN, WAN (green/orange), 2.4G, 5G, USB

All five front jacks are switch ports: the blue “WAN” jack is wan, LAN1-4 are lan1-lan4.

The stock web UI and the TP-Link web recovery cannot install OpenWrt directly: the recovery only accepts images signed by TP-Link. There are two ways in.

Whatever method you use, boot the initramfs first and check the switch before the permanent install. With serial it runs from RAM and nothing changes on flash. Without serial it goes into the unused slot, and stock stays untouched in the other one. On the running initramfs:

dmesg | grep rtl8365mb
  • found an RTL8367S switch: supported, continue.
  • Anything else, or no such line: stop. Power-cycle back to stock (serial method) or use the web recovery (serial-free method).

See Serial for the header. The RX trace is gapped from the factory and has to be bridged before you can type.

  1. Set your PC to 192.168.1.10 and serve the initramfs-uImage.itb over TFTP.
  2. Power on and interrupt U-Boot on the console.
  3. Boot the initramfs:
    setenv serverip 192.168.1.10
    setenv ipaddr 192.168.1.1
    tftpboot 0x44000000 openwrt-qualcommax-ipq50xx-tplink_archer-ax55-v1-initramfs-uImage.itb
    bootm 0x44000000
  4. Do the switch check (Step 0).
  5. Copy the squashfs-sysupgrade.bin to /tmp and run sysupgrade -n /tmp/<file>.

The sysupgrade writes OpenWrt into the inactive slot and switches the boot slot to it.

This uses a repacked stock firmware with telnet enabled, based on lmadarassy/tp-link-ax55-fw-hacks. It has been done on a unit shipped with stock 1.5.10. The steps below are the ones used there, written down after the fact, so read them through before you start.

  1. Get an unencrypted stock image. The 2025 stock firmware (v1.5.10) is encrypted and cannot be repacked. Use the 2024 build (Archer AX55(EU)_V1_240628, v1.3.3) or older.
  2. Repack it with telnet. Run the repo's 01-unpack.sh as root, otherwise /dev/console is lost from the root filesystem. Add this line before exit 0 in squashfs-root/etc/rc.local:
    telnetd -l /bin/sh &

    Then run 02-repack.sh as root.

  3. Flash it from the firmware upgrade page of the stock web UI. This path checks only an MD5 checksum, and a unit running 1.5.10 accepted the older, repacked image. After the reboot, telnet 192.168.0.1 gives a root shell without a password. Keep that unit off untrusted networks until you have finished.
  4. Copy the OpenWrt initramfs-factory.ubi to the router, e.g. with python3 -m http.server 8000 on the PC (192.168.0.10):
    cd /tmp
    wget http://192.168.0.10:8000/openwrt-qualcommax-ipq50xx-tplink_archer-ax55-v1-initramfs-factory.ubi -O factory.ubi
    md5sum factory.ubi

    Compare the checksum with the file on your PC.

  5. Find the inactive slot. tp_boot_idx is the slot the bootloader uses: 0 = rootfs, 1 = rootfs_1.
    fw_printenv tp_boot_idx
    cat /proc/mtd | grep -E '"rootfs"|"rootfs_1"'

    Write to the slot that is not in use. On the unit this was done on, stock ran from rootfs_1 (tp_boot_idx=1), and rootfs was /dev/mtd11. Check yours; do not copy the number.

  6. Write it and switch the slot (example for rootfs = mtd11):
    mtd erase /dev/mtd11
    mtd write /tmp/factory.ubi /dev/mtd11
    fw_setenv tp_boot_idx 0
    fw_setenv config_name config@mp03.3
    reboot
  7. The router boots OpenWrt from RAM at 192.168.1.1. Connect a cable to a LAN port and do the switch check (Step 0). On an RTL8367S-VB unit you will not get this far: there is no wired network and no Wi-Fi, so go straight to the web recovery.
  8. Copy the squashfs-sysupgrade.bin over (scp -O) and run sysupgrade -n /tmp/<file>. This replaces the slot the stock firmware was in. Stock stays available through the web recovery.

sysupgrade works as on any other device. It always writes to the inactive slot and then points tp_boot_idx at it, so the previous image stays in the other slot. Note: the bootloader falls back to the other slot only when the new kernel fails to load. It has no boot counter, so a kernel that loads and then crashes is not caught, and in that case the web recovery is the way out.

This needs no serial and works whatever is in flash:

  1. Download an official firmware for the Archer AX55 v1 from TP-Link.
  2. Set your PC to 192.168.0.10 / 255.255.255.0 and connect it to a LAN port.
  3. Hold Reset while powering the router on, for about 10 seconds.
  4. Open http://192.168.0.1 and upload the TP-Link image.

The recovery accepts only images signed by TP-Link, so it cannot be used to install OpenWrt.

  • RTL8367S-VB units have no wired ports on current OpenWrt. Support is being worked on in PR #19644.
  • Wired network dead after some boots. On RTL8367S units the link between the SoC and the switch occasionally comes up broken: no IP and no traffic on any wired port, while Wi-Fi works. A reboot may or may not clear it; a power cycle is more reliable. A fix is proposed in PR #25153. If you hit it, please report it in the forum thread with the output of ethtool -S eth0 | grep p06.
  • Wi-Fi is off after the first boot, as on most OpenWrt devices. Enable it through a wired connection.
  • Routing speed is limited by the CPU. OpenWrt has no NSS offload for the IPQ5018, so NAT runs on the two A53 cores. Two settings help: enable Software flow offloading (Network → Firewall), and move the ethernet interrupt to the second core in /etc/rc.local:
    irq=$(awk '/eth0/ {sub(":","",$1); print $1}' /proc/interrupts)
    [ -n "$irq" ] && echo 2 > /proc/irq/$irq/smp_affinity

    On one unit this took wired LAN-to-WAN NAT from 183 to 341 Mbit/s. Leave “Packet steering” off. Both settings are lost on a sysupgrade that does not keep the configuration.

JP1, 4-pin header (triangle marks pin 1): 1 TX, 2 RX, 3 GND, 4 VCC. 115200 8N1, 1.8 V logic. Do not connect a 3.3 V adapter to RX.

TP-Link leaves a gap in the RX trace, so the console is read-only until the gap is bridged; where exactly depends on the board revision. Reading the boot log needs no modification.

The factory MAC is the default-mac file in the tp_data UBI volume. LAN and the conduit use the label MAC, WAN uses label + 1, and the two radios use label + 2 and + 3.

Physical partitions
MTD Name Start End Size (KiB) Notes
mtd0 0:SBL1 0x00000000 0x00080000 512
mtd1 0:MIBIB 0x00080000 0x00100000 512
mtd2 0:BOOTCONFIG 0x00100000 0x00140000 256
mtd3 0:BOOTCONFIG1 0x00140000 0x00180000 256
mtd4 0:QSEE 0x00180000 0x00280000 1024
mtd5 0:DEVCFG 0x00280000 0x002C0000 256
mtd6 0:CDT 0x002C0000 0x00300000 256
mtd7 0:APPSBLENV 0x00300000 0x00380000 512 U-Boot environment (tp_boot_idx)
mtd8 0:APPSBL 0x00380000 0x004C0000 1280 U-Boot
mtd9 0:ART 0x004C0000 0x005C0000 1024 Wi-Fi calibration data. Back up!
mtd10 0:TRAINING 0x005C0000 0x00640000 512
mtd11 rootfs 0x00640000 0x03040000 43008 Firmware slot 0 (UBI)
mtd12 rootfs_1 0x03040000 0x05A40000 43008 Firmware slot 1 (UBI)
mtd13 tp_data 0x05A40000 0x06280000 8448 UBI with a UBIFS volume, contains the factory MAC. Back up!
mtd14 radio 0x06280000 0x066C0000 4352
mtd15 data 0x066C0000 0x06740000 512
UBI instances (stock kernel)
UBI device Attached MTD Volumes Notes
ubi0 mtd12 (rootfs_1) kernel, ubi_rootfs (SquashFS), rootfs_data Firmware slot.
ubi1 mtd13 (tp_data) tp_data (UBIFS) Mounted read-write by the stock firmware.
UBI volumes (virtual MTDs) *
MTD Name Size (bytes) Size (KiB)
mtd16 kernel 0x00439CB8 4327
mtd17 ubi_rootfs 0x020F0000 33728
mtd18 rootfs_data 0x0009B000 620
mtd19 tp_data 0x0064C000 6448

* - Sizes of the UBI volumes (mtd16-mtd19) shown above may differ on other versions. Do not use them as reference values.

The kernel, ubi_rootfs and rootfs_data volumes live inside whichever slot is currently active, which is selected by tp_boot_idx (0 / 1).

Note: The partitions 0:ART, tp_data contain vendor specific data about your router, such as Wi-Fi calibration data and MAC addresses. It is a good idea to make a backup of them before flashing anything.

  • Last modified: 2026/10/02 10:38
  • by moon1337