TP-Link Archer AX55 v1
This image is for the Archer AX55 v1 only. Other revisions and similarly named models use different hardware and must not be flashed with it:
- AX55 Pro v1: has 2.5 Gbit ports, so its ethernet hardware differs from the v1. It is not supported, and the AX55 v1 images are not meant for it. See AX55 Pro v1 below.
- AX55 v2: different hardware, not supported by this image.
- AX55 v4: different hardware, not supported by this image. See the forum thread.
The revision is printed on the label on the bottom of the router (the “Ver.” field). If it does not say 1.0, stop here.
Two switch variants are sold as “Archer AX55 v1”. Some units have a Realtek RTL8367S switch, which is supported. Others have an RTL8367S-VB, which current OpenWrt does not support yet. On an -VB unit OpenWrt boots with no working wired ports, and because Wi-Fi is off by default you cannot reach it at all. The unit is not bricked (the web recovery always works), but check your switch before you write anything to flash. How to check is described under Installation.
The TP-Link Archer AX55 v1 is a dual-band Wi-Fi 6 router (IPQ5018) with 5 gigabit ethernet ports and one USB 3.0 port. It is supported in OpenWrt snapshots since commit 8ac63a1c35.
Supported Versions
Snapshot images are in targets/qualcommax/ipq50xx. There is no stable release with this device yet.
| Image | Use |
|---|---|
...-tplink_archer-ax55-v1-initramfs-uImage.itb | Boots from RAM over TFTP (serial install). Nothing is written to flash. |
...-tplink_archer-ax55-v1-initramfs-factory.ubi | The same RAM image as a UBI image, written from the stock firmware (serial-free install). |
...-tplink_archer-ax55-v1-squashfs-sysupgrade.bin | The permanent install and later upgrades, flashed from a running OpenWrt. |
...-tplink_archer-ax55-v1-squashfs-factory.ubi | Full UBI image of the permanent install. |
Hardware Highlights
| SoC | Qualcomm IPQ5018, 2 × Cortex-A53 |
|---|---|
| Switch | Realtek RTL8367S or RTL8367S-VB (see the warning above), connected to the SoC over a 2.5G HSGMII link |
| Flash | two firmware slots, see Flash layout |
| Buttons | Reset, WPS/Wi-Fi |
| LEDs | power, LAN, WAN (green/orange), 2.4G, 5G, USB |
All five front jacks are switch ports: the blue “WAN” jack is wan, LAN1-4 are lan1-lan4.
Installation
The stock web UI and the TP-Link web recovery cannot install OpenWrt directly: the recovery only accepts images signed by TP-Link. There are two ways in.
Step 0: check the switch
Whatever method you use, boot the initramfs first and check the switch before the permanent install. With serial it runs from RAM and nothing changes on flash. Without serial it goes into the unused slot, and stock stays untouched in the other one. On the running initramfs:
dmesg | grep rtl8365mb
found an RTL8367S switch: supported, continue.- Anything else, or no such line: stop. Power-cycle back to stock (serial method) or use the web recovery (serial-free method).
Method 1: serial console (recommended)
See Serial for the header. The RX trace is gapped from the factory and has to be bridged before you can type.
- Set your PC to
192.168.1.10and serve theinitramfs-uImage.itbover TFTP. - Power on and interrupt U-Boot on the console.
- Boot the initramfs:
setenv serverip 192.168.1.10 setenv ipaddr 192.168.1.1 tftpboot 0x44000000 openwrt-qualcommax-ipq50xx-tplink_archer-ax55-v1-initramfs-uImage.itb bootm 0x44000000
- Do the switch check (Step 0).
- Copy the
squashfs-sysupgrade.binto/tmpand runsysupgrade -n /tmp/<file>.
The sysupgrade writes OpenWrt into the inactive slot and switches the boot slot to it.
Method 2: without serial (advanced)
This uses a repacked stock firmware with telnet enabled, based on lmadarassy/tp-link-ax55-fw-hacks. It has been done on a unit shipped with stock 1.5.10. The steps below are the ones used there, written down after the fact, so read them through before you start.
- Get an unencrypted stock image. The 2025 stock firmware (v1.5.10) is encrypted and cannot be repacked. Use the 2024 build (
Archer AX55(EU)_V1_240628, v1.3.3) or older. - Repack it with telnet. Run the repo's
01-unpack.shas root, otherwise/dev/consoleis lost from the root filesystem. Add this line beforeexit 0insquashfs-root/etc/rc.local:telnetd -l /bin/sh &
Then run
02-repack.shas root. - Flash it from the firmware upgrade page of the stock web UI. This path checks only an MD5 checksum, and a unit running 1.5.10 accepted the older, repacked image. After the reboot,
telnet 192.168.0.1gives a root shell without a password. Keep that unit off untrusted networks until you have finished. - Copy the OpenWrt
initramfs-factory.ubito the router, e.g. withpython3 -m http.server 8000on the PC (192.168.0.10):cd /tmp wget http://192.168.0.10:8000/openwrt-qualcommax-ipq50xx-tplink_archer-ax55-v1-initramfs-factory.ubi -O factory.ubi md5sum factory.ubi
Compare the checksum with the file on your PC.
- Find the inactive slot.
tp_boot_idxis the slot the bootloader uses:0=rootfs,1=rootfs_1.fw_printenv tp_boot_idx cat /proc/mtd | grep -E '"rootfs"|"rootfs_1"'
Write to the slot that is not in use. On the unit this was done on, stock ran from
rootfs_1(tp_boot_idx=1), androotfswas/dev/mtd11. Check yours; do not copy the number. - Write it and switch the slot (example for
rootfs=mtd11):mtd erase /dev/mtd11 mtd write /tmp/factory.ubi /dev/mtd11 fw_setenv tp_boot_idx 0 fw_setenv config_name config@mp03.3 reboot
- The router boots OpenWrt from RAM at
192.168.1.1. Connect a cable to a LAN port and do the switch check (Step 0). On an RTL8367S-VB unit you will not get this far: there is no wired network and no Wi-Fi, so go straight to the web recovery. - Copy the
squashfs-sysupgrade.binover (scp -O) and runsysupgrade -n /tmp/<file>. This replaces the slot the stock firmware was in. Stock stays available through the web recovery.
Upgrading OpenWrt
sysupgrade works as on any other device. It always writes to the inactive slot and then points tp_boot_idx at it, so the previous image stays in the other slot. Note: the bootloader falls back to the other slot only when the new kernel fails to load. It has no boot counter, so a kernel that loads and then crashes is not caught, and in that case the web recovery is the way out.
Recovery
Return to OEM
This needs no serial and works whatever is in flash:
- Download an official firmware for the Archer AX55 v1 from TP-Link.
- Set your PC to
192.168.0.10/255.255.255.0and connect it to a LAN port. - Hold Reset while powering the router on, for about 10 seconds.
- Open
http://192.168.0.1and upload the TP-Link image.
The recovery accepts only images signed by TP-Link, so it cannot be used to install OpenWrt.
Known issues
- RTL8367S-VB units have no wired ports on current OpenWrt. Support is being worked on in PR #19644.
- Wired network dead after some boots. On RTL8367S units the link between the SoC and the switch occasionally comes up broken: no IP and no traffic on any wired port, while Wi-Fi works. A reboot may or may not clear it; a power cycle is more reliable. A fix is proposed in PR #25153. If you hit it, please report it in the forum thread with the output of
ethtool -S eth0 | grep p06. - Wi-Fi is off after the first boot, as on most OpenWrt devices. Enable it through a wired connection.
- Routing speed is limited by the CPU. OpenWrt has no NSS offload for the IPQ5018, so NAT runs on the two A53 cores. Two settings help: enable Software flow offloading (Network → Firewall), and move the ethernet interrupt to the second core in
/etc/rc.local:irq=$(awk '/eth0/ {sub(":","",$1); print $1}' /proc/interrupts) [ -n "$irq" ] && echo 2 > /proc/irq/$irq/smp_affinityOn one unit this took wired LAN-to-WAN NAT from 183 to 341 Mbit/s. Leave “Packet steering” off. Both settings are lost on a sysupgrade that does not keep the configuration.
Hardware details
Serial
JP1, 4-pin header (triangle marks pin 1): 1 TX, 2 RX, 3 GND, 4 VCC. 115200 8N1, 1.8 V logic. Do not connect a 3.3 V adapter to RX.
TP-Link leaves a gap in the RX trace, so the console is read-only until the gap is bridged; where exactly depends on the board revision. Reading the boot log needs no modification.
MAC addresses
The factory MAC is the default-mac file in the tp_data UBI volume. LAN and the conduit use the label MAC, WAN uses label + 1, and the two radios use label + 2 and + 3.
Flash layout
| Physical partitions | |||||
|---|---|---|---|---|---|
| MTD | Name | Start | End | Size (KiB) | Notes |
| mtd0 | 0:SBL1 | 0x00000000 | 0x00080000 | 512 | |
| mtd1 | 0:MIBIB | 0x00080000 | 0x00100000 | 512 | |
| mtd2 | 0:BOOTCONFIG | 0x00100000 | 0x00140000 | 256 | |
| mtd3 | 0:BOOTCONFIG1 | 0x00140000 | 0x00180000 | 256 | |
| mtd4 | 0:QSEE | 0x00180000 | 0x00280000 | 1024 | |
| mtd5 | 0:DEVCFG | 0x00280000 | 0x002C0000 | 256 | |
| mtd6 | 0:CDT | 0x002C0000 | 0x00300000 | 256 | |
| mtd7 | 0:APPSBLENV | 0x00300000 | 0x00380000 | 512 | U-Boot environment (tp_boot_idx) |
| mtd8 | 0:APPSBL | 0x00380000 | 0x004C0000 | 1280 | U-Boot |
| mtd9 | 0:ART | 0x004C0000 | 0x005C0000 | 1024 | Wi-Fi calibration data. Back up! |
| mtd10 | 0:TRAINING | 0x005C0000 | 0x00640000 | 512 | |
| mtd11 | rootfs | 0x00640000 | 0x03040000 | 43008 | Firmware slot 0 (UBI) |
| mtd12 | rootfs_1 | 0x03040000 | 0x05A40000 | 43008 | Firmware slot 1 (UBI) |
| mtd13 | tp_data | 0x05A40000 | 0x06280000 | 8448 | UBI with a UBIFS volume, contains the factory MAC. Back up! |
| mtd14 | radio | 0x06280000 | 0x066C0000 | 4352 | |
| mtd15 | data | 0x066C0000 | 0x06740000 | 512 | |
| UBI instances (stock kernel) | |||
|---|---|---|---|
| UBI device | Attached MTD | Volumes | Notes |
| ubi0 | mtd12 (rootfs_1) | kernel, ubi_rootfs (SquashFS), rootfs_data | Firmware slot. |
| ubi1 | mtd13 (tp_data) | tp_data (UBIFS) | Mounted read-write by the stock firmware. |
| UBI volumes (virtual MTDs) * | |||
|---|---|---|---|
| MTD | Name | Size (bytes) | Size (KiB) |
| mtd16 | kernel | 0x00439CB8 | 4327 |
| mtd17 | ubi_rootfs | 0x020F0000 | 33728 |
| mtd18 | rootfs_data | 0x0009B000 | 620 |
| mtd19 | tp_data | 0x0064C000 | 6448 |
* - Sizes of the UBI volumes (mtd16-mtd19) shown above may differ on other versions. Do not use them as reference values.
The kernel, ubi_rootfs and rootfs_data volumes live inside whichever slot is currently active, which is selected by tp_boot_idx (0 / 1).
Note: The partitions 0:ART, tp_data contain vendor specific data about your router, such as Wi-Fi calibration data and MAC addresses. It is a good idea to make a backup of them before flashing anything.
Notes
OpenWrt Forum threads:
AX55
- https://forum.openwrt.org/t/support-for-new-tp-link-archer-ax55-v4/207485 (v4: different hardware, not covered here)
AX55 Pro

