PT-2026-36293 · Lighttpd+1 · Lighttpd+1
Newym
·
Published
2026-05-01
·
Updated
2026-05-01
·
CVE-2026-7546
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Totolink NR1800X version 9.1.0u.6279 B20210910
Description
A stack-based buffer overflow exists in the lighttpd component. This issue occurs when the
find host ip() function improperly handles the Host argument, allowing a remote attacker to execute the attack.Recommendations
Update Totolink NR1800X version 9.1.0u.6279 B20210910 to a patched version.
As a temporary workaround, restrict access to the lighttpd component to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nr1800X
Lighttpd