CYBERHAWK / CVE / CVE-2026-7546

CVE-2026-7546

Totolink NR1800X

CRITICAL CVSS 9.8 other

The flaw

Stack-based buffer overflow in lighttpd find_host_ip function via Host header manipulation.

What to do

Update firmware beyond 9.1.0u.6279_B20210910

▸ Scan my repo for CVE-2026-7546

References

First seen 2026-05-01 · Tracked by PickBits CyberHawk · Weekly CVE digest