📦 Nr1800x Firmware

by Totolink

🔍 What is Nr1800x Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-45841

CRITICAL CVSS 9.8 May 8, 2025

This vulnerability allows authenticated attackers to execute arbitrary code on TOTOLINK NR1800X routers by exploiting a stack overflow in the setSmsCfg function. Attackers with valid credentials can g...

CVE-2023-36340

CRITICAL CVSS 9.8 Oct 16, 2023

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK NR1800X routers by exploiting a stack overflow in the loginAuth function via the http_host parameter. Attackers can gai...

CVE-2026-1328

HIGH CVSS 8.8 Jan 22, 2026

A buffer overflow vulnerability in Totolink NR1800X routers allows remote attackers to execute arbitrary code by sending specially crafted POST requests to the setWizardCfg function. This affects rout...

CVE-2025-45843

HIGH CVSS 8.8 May 8, 2025

This vulnerability allows authenticated attackers to execute arbitrary code on TOTOLINK NR1800X routers via a stack overflow in the WiFi guest configuration function. Attackers with valid credentials ...

CVE-2025-45845

HIGH CVSS 8.8 May 8, 2025

This vulnerability allows authenticated attackers to execute arbitrary code on TOTOLINK NR1800X routers via a stack overflow in the setWiFiEasyGuestCfg function. Attackers with valid credentials can e...

CVE-2024-35388

HIGH CVSS 8.8 May 24, 2024

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK NR1800X routers via a stack overflow in the urldecode function's password parameter. Attackers can potentially gain ful...

CVE-2026-1326

MEDIUM CVSS 6.3 Jan 22, 2026

This CVE describes a command injection vulnerability in Totolink NR1800X routers that allows remote attackers to execute arbitrary commands on affected devices. The vulnerability exists in the web int...

CVE-2026-1327

MEDIUM CVSS 6.3 Jan 22, 2026

This CVE describes a remote command injection vulnerability in Totolink NR1800X routers. Attackers can execute arbitrary commands on affected devices by sending specially crafted POST requests to the ...

CVE-2025-60684

MEDIUM CVSS 6.5 Nov 13, 2025

A stack buffer overflow vulnerability in ToToLink router firmware allows unauthenticated attackers to execute arbitrary code or cause memory corruption by sending specially crafted 'lang' parameter va...

CVE-2025-60686

MEDIUM CVSS 5.1 Nov 13, 2025

This vulnerability allows local attackers to trigger stack-based buffer overflows in ToToLink router firmware by manipulating ARP table data. Attackers can cause denial of service or potentially execu...

CVE-2025-60688

MEDIUM CVSS 6.5 Nov 13, 2025

A stack buffer overflow vulnerability in ToToLink router firmware allows unauthenticated attackers to execute arbitrary code or crash devices by sending specially crafted web requests. This affects To...