CVE-2026-7546

CRITICAL

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument ...

Affects 0 products across 3 vendors.

BCS6.1
CVSS 3.19.8
CVSS v48.9
EPSS0.8%
Percentile52th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-119: Improper Restriction of Operations within Memory Buffer

Parent class for buffer-related vulnerabilities where operations exceed buffer boundaries.

CWE-121: Stack-Based Buffer Overflow

Buffer overflow corrupting the program stack, typically overwriting the return address for code execution.

Related Attack Patterns (CAPEC)
CAPEC-8 Buffer Overflow in an API Call
via CWE-119
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-119
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-119
CAPEC-14 Client-side Injection-induced Buffer Overflow
via CWE-119
CAPEC-24 Filter Failure through Buffer Overflow
via CWE-119
Show all 12

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical security vulnerability exists in Totolink NR1800X 9.1.0u.6279_B20210910 affecting the lighttpd component through the function find_host_ip, leading to a stack-based buffer overflow via manipulation of the Host argument.

BSID: BS-2026-GLOBAL-271057-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-7546?
A critical security vulnerability exists in Totolink NR1800X 9.1.0u.6279_B20210910 affecting the lighttpd component through the function find_host_ip, leading to a stack-based buffer overflow via manipulation of the Host argument.
What is the CVSS score for CVE-2026-7546?
CVE-2026-7546 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.8%.
Is CVE-2026-7546 actively exploited?
No confirmed active exploitation of CVE-2026-7546 as of 2026-05-30.
How do I remediate CVE-2026-7546?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-7546?
CVE-2026-7546 affects: Element, Lighttpd, Totolink.
Vulnerability Details
CVE IDCVE-2026-7546
BSIDBS-2026-GLOBAL-271057-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-05-01
Last Modified2026-05-01
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited remotely by sending a specially crafted HTTP request with a malicious Host header to the affected device. This can lead to arbitrary code execution with the privileges of the lighttpd process.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Element —
Lighttpd —
Totolink —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 117 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash386a89e58667b9d18daba117342c023d36468d949ab0127d60df501d4eb7db088d515e56bb4c245bbf5dbc45e2a7538503b753d1b0850cfe4311903fd7cfe6bb
Related CVEs affecting Element
CVE-2024-32962 10.0 xml-crypto is an xml digital signature and encryption library for Node.js. In... CVE-2024-56829 10.0 Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary... CVE-2026-7243 9.8 A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The a... CVE-2026-6279 9.8 The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unau... CVE-2026-7719 9.8 A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. T...
View all Element CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →