CVE-2026-3485 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 3, 2026
D-Link DIR-868L - Command Injection
Published: March 3, 2026Updated: March 3, 2026Remote Exploitable
Overview
D-Link DIR-868L 110b03 contains a command injection caused by manipulation of the "ST" argument in SSDP Service sub_1BF84 function, letting remote attackers execute OS commands, exploit requires network access.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Remote attackers can execute arbitrary OS commands, potentially leading to full system compromise.
Mitigation
Upgrade to the latest supported version or replace the device as it is no longer supported.
References
Related Resources
Details
- CVE ID
- CVE-2026-3485
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- unconfirmed
CWE
- CWE-77
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H