LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3485 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 3, 2026

D-Link DIR-868L - Command Injection

Published: March 3, 2026Updated: March 3, 2026Remote Exploitable

Overview

D-Link DIR-868L 110b03 contains a command injection caused by manipulation of the "ST" argument in SSDP Service sub_1BF84 function, letting remote attackers execute OS commands, exploit requires network access.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Remote attackers can execute arbitrary OS commands, potentially leading to full system compromise.

Mitigation

Upgrade to the latest supported version or replace the device as it is no longer supported.

Details

CVE ID
CVE-2026-3485
Severity
Critical
CVSS Score
9.8
Type
command_injection
Status
unconfirmed

CWE

  • CWE-77

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H