Executive brief
A critical security vulnerability has been identified in the Totolink NR1800X wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to remotely crash the device or potentially take full control of it without needing a password. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.
Technical details
A stack-based buffer overflow (CWE-121) exists in the Form_Logout function within the vendor-customized lighttpd binary (/usr/sbin/lighttpd) of the Totolink NR1800X firmware version 9.1.0u.6279_B20210910. The vulnerability is located in the /formLogout.htm endpoint, where the userloginAuth() function fails to perform authentication or session validation before processing the request. An attacker can trigger the overflow by sending a GET request to /formLogout.htm with a Host header exceeding 245 bytes, which is then processed by an unsafe strcpy() operation. This allows for remote code execution (RCE) or denial of service (DoS) without any user interaction or valid credentials.
Affected products
- Totolink NR1800X 9.1.0u.6279_B20210910
Timeline
- 2026-06-11: disclosed: Initial discovery and PoC published on GitHub
- 2026-07-14: advisory: CVE published to NVD dataset