CVE-2026-7546: Totolink NR1800X lighttpd find_host_ip stack-based overflow
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279B20210910. The impacted element is the function findhostip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7546?
CVE-2026-7546 is classified as a critical vulnerability due to its potential for stack-based buffer overflow.
How do I fix CVE-2026-7546?
To fix CVE-2026-7546, it is recommended to update the Totolink NR1800X firmware to the latest version provided by the manufacturer.
What impact does CVE-2026-7546 have on my device?
CVE-2026-7546 can allow an attacker to execute arbitrary code on the Totolink NR1800X, leading to full device compromise.
Is CVE-2026-7546 remotely exploitable?
Yes, CVE-2026-7546 can be remotely exploited by manipulating the Host argument sent to the lighttpd service.
Which versions of Totolink NR1800X are affected by CVE-2026-7546?
CVE-2026-7546 affects Totolink NR1800X firmware version 9.1.0u.6279_B20210910.