Vulnerability Description
A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-868L Firmware | 110b03 |
| Dlink | Dir-868L | - |
Related Weaknesses (CWE)
References
- https://kn0sinna.notion.site/dlink-dir-868l-ssdp-command-injection-30eb1876cd6e8ExploitThird Party Advisory
- https://vuldb.com/?ctiid.348560Permissions RequiredVDB Entry
- https://vuldb.com/?id.348560Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.764759Third Party AdvisoryVDB Entry
- https://www.dlink.com/Product
FAQ
What is CVE-2026-3485?
CVE-2026-3485 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to ...
How severe is CVE-2026-3485?
CVE-2026-3485 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-3485?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-868L Firmware, Dlink Dir-868L.