216.73.217.98

CVE-2026-3485

· Published 03/03/2026 21:16 · Modified 04/03/2026 14:07

Labels: CVE-2026-3485 2026-03-03CVE-2026-3485CWE-77CWE-78[email protected]

Essential information

Published
03/03/2026 21:16
Modified
04/03/2026 14:07
Author
Creator
CVSS
8.9 HIGH (v3) 8.9 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

NVD status

Status
Analyzed — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dlink / dir-868l firmware cpe:2.3:o:dlink:dir-868l_firmware:110b03:*:*:*:*:*:*:*
dlink / dir-868l cpe:2.3:h:dlink:dir-868l:-:*:*:*:*:*:*:*

References