CVE-2026-7546: Totolink NR1800X

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

Affected products

  • Totolink NR1800X: version 9.1.0u.6279_B20210910 only

Published 2026-05-01. Last modified 2026-06-17.