CVE-2026-7546: Totolink NR1800X
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected products
- Totolink NR1800X: version 9.1.0u.6279_B20210910 only
Published 2026-05-01. Last modified 2026-06-17.