


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttp…
Published:
30 april 2026 om 22:00:00
Alert date:
1 mei 2026 om 04:01:07
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A stack-based buffer overflow vulnerability (CVE-2026-7546) has been discovered in Totolink NR1800X router firmware version 9.1.0u.6279_B20210910. The vulnerability exists in the find_host_ip function of the lighttpd component and can be triggered by manipulating the Host argument. This vulnerability can be exploited remotely and public exploits are available, making it a high-risk security issue for affected devices.
Technical details
Mitigation steps:
Affected products:
Totolink NR1800X
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7546
https://github.com/newym/cve/blob/main/totolinknr1800x.md
https://vuldb.com/submit/804404
https://vuldb.com/vuln/360357
https://vuldb.com/vuln/360357/cti
https://www.totolink.net/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
