CVE-2023-36340: Totolink NR1800X Firmware

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

Affected products

  • Totolink NR1800X Firmware: version 9.1.0u.6279_b20210910 only

Published 2023-10-16. Last modified 2026-06-17.