CVE-2026-7546Disclosure

LOWCVSS 8.9 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 5 classified signals
  • Peaked at 6 mentions on most recent observed day (2026-05-15)
  • 11 total mentions across 2 days

Deep dive

Activity timeline11 mentions / 2d
02356Mentions · 2026-05-01: 5Mentions · 2026-05-15: 6Patch / Workaround · 2026-05-01: 1Technical Details · 2026-05-01: 5Technical Details · 2026-05-15: 405-0105-15
Signal classification3 categories
Disclosure
545.5%
General
545.5%
Patch
19.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-015
Disclosure3General1Patch1
2026-05-156
Disclosure2General4
Full discourse11 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-7546 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post simply lists a high‑severity CVE with its CVSS score and severity level, without offering any proof of concept, exploit code, active exploitation evidence, or remediation guidance.

    1001051
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-7546 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text merely lists the CVE identifier, its CVSS score, severity level, and advisory status, with no evidence of exploitation, mitigation, or detailed technical exploit information.

    1000040
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-7546 (CVSS 9.8) — multiple products. CVE: CVE-2026-7546 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A new critical vulnerability, CVE-2026-7546, has been publicly disclosed with detailed CVSS metrics and severity information, but no evidence of exploitation, PoC, or mitigation guidance is provided.

    1000037
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7546 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279B20210910.

    Post summary

    A critical vulnerability (CVE-2026-7546) was identified in the Totolink NR1800X router (firmware 9.1.0u.6279B20210910) with a high CVSS score; no PoC, exploit, or patch information is provided.

    1000038
    215 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7546 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7546 #CVE-2026-7546 #CVE #Critical #CyberSecurity #InfoSec https://t.co/N0uDjisPfG

    Post summary

    The tweet announces CVE-2026-7546 as a new critical vulnerability with a CVSS score of 9.8, but provides no further details, exploit code, or mitigation information.

    0001076
    151 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-7546 — CVSS 9.8/10 ██████████ A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/taEPP9jnNM

    Post summary

    The tweet announces CVE‑2026‑7546, a critical vulnerability with a CVSS of 9.8 in Totolink NR1800X, and indicates that a patch is now available.

    1000042
    26 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7546-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text only references a URL and hashtags without substantive details, so no actionable indicators can be confirmed.

    0000028
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7546-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text merely references a URL and hashtags without providing concrete details about the CVE.

    0000028
    215 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7546 A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such … https://www.cve.org/CVERecord?id=CVE-2026-7546 ----- Traducción: CVE-2026-7546 Se … http://infoflow.cloud`

    Post summary

    A new vulnerability (CVE‑2026‑7546) has been announced for Totolink routers, affecting the lighttpd component’s find_host_ip function. No PoC, exploit, patch, or evidence of active exploitation is reported.

    0000026
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7546 A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such … https://www.cve.org/CVERecord?id=CVE-2026-7546

    Post summary

    The text reports that CVE-2026-7546 was detected in Totolink NR1800X, affecting the find_host_ip function of lighttpd, but does not provide info on patches, PoC, or exploitation.

    00000146
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7546 Stack-Based Buffer Overflow in Totolink NR1800X 9.1.0u.6279_B20210910 lighttpd https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7546

    Post summary

    The post reports CVE-2026-7546 as a stack-based buffer overflow in Totolink NR1800X lighttpd, but supplies no PoC, exploit code, or evidence of active use.

    0000043
    4.0K followersView on X

Explore more