


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttp…
Published:
30 April 2026 at 22:00:00
Alert date:
1 May 2026 at 16:05:43
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A stack-based buffer overflow vulnerability (CVE-2026-7546) has been discovered in Totolink NR1800X router firmware version 9.1.0u.6279_B20210910. The vulnerability affects the find_host_ip function within the lighttpd component, where manipulation of the Host argument leads to a buffer overflow condition. This security flaw can be exploited remotely by attackers, making it particularly dangerous for network infrastructure. The exploit code has been publicly disclosed and is available for use, significantly increasing the risk to affected devices. Organizations using this specific Totolink router model should prioritize patching or implementing protective measures immediately.
Technical details
Mitigation steps:
Affected products:
Totolink NR1800X
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7546
https://github.com/newym/cve/blob/main/totolinknr1800x.md
https://vuldb.com/submit/804404
https://vuldb.com/vuln/360357
https://vuldb.com/vuln/360357/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
