Handler on Duty: Brad Duncan
Threat Level: green
| Published | 2026-05-01 03:16:01 |
|---|---|
| Last Modified | 2026-05-01 03:16:01 |
| AKA | CVE-2026-7546 |
| Summary | A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. |
| CVSS Score | 10 |
| Access Vector | Local | Adjacent | Network |
|---|---|---|---|
| Access Complexity | Low | Medium | High |
| Authentication | None | Single | Multiple |
| Confidentiality | None | Partial | Complete |
| Integrity | None | Partial | Complete |
| Availability | None | Partial | Complete |