CVE-2026-3485 describes a critical OS command injection vulnerability in the D-Link DIR-868L router (firmware 110b03). This flaw resides in the SSDP Service's sub_1BF84 function, allowing remote attackers to execute arbitrary commands by manipulating the 'ST' argument. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While an exploit has been published, there is no evidence of active exploitation, and it lacks significant community discussion or media coverage, likely because it affects an end-of-life product.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
110b03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-868l_firmware:110b03:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.