CVE-2026-3485

A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://kn0sinna.notion.site/dlink-dir-868l-ssdp-command-injection-30eb1876cd6e80caa691de6fe5cab59c Exploit Third Party Advisory
https://vuldb.com/?ctiid.348560 Permissions Required VDB Entry
https://vuldb.com/?id.348560 Third Party Advisory VDB Entry
https://vuldb.com/?submit.764759 Third Party Advisory VDB Entry
https://www.dlink.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dir-868l_firmware:110b03:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-868l:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-03 21:16

Updated : 2026-03-04 14:07


NVD link : CVE-2026-3485

Mitre link : CVE-2026-3485

CVE.ORG link : CVE-2026-3485


JSON object : View

Products Affected

dlink

  • dir-868l_firmware
  • dir-868l
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')