CVE-2026-3485Disclosure(dlink / dir-868l)

MEDIUMCVSS 8.9 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch dlink dir-868l systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-868l
  • dir-868l_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-03); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
dir-868ldir-868l_firmware

2 versions affected across 2 products

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-03-03: 4Mentions · 2026-03-04: 3Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-04: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-03: 3Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0303-0403-0503-06
Signal classification4 categories
Disclosure
555.6%
Patch
222.2%
Active Exploitation
111.1%
PoC
111.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-034
Disclosure4
2026-03-043
Active Exploitation1Disclosure1PoC1
2026-03-051
Patch1
2026-03-061
Patch1
Full discourse9 posts
  • NCIIPC India@NCIIPC
    Patch

    OS Command Injection Vulnerability discovered in #D-Link. Users are advised to follow OEM Security Advisory to remain safe! #CVE-2026-3485 https://nvd.nist.gov/vuln/detail/CVE-2026-3485

    Post summary

    A newly discovered OS command injection bug in D‑Link devices is announced, and users are advised to follow the OEM security advisory for patching or mitigation.

    10000194
    8.4K followersView on X
  • Sami Laiho@samilaiho
    Patch

    dlink dir-868l ssdp command injection URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3485 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.9

    Post summary

    CVE‑2026‑3485 affects the D‑Link DIR‑868L by enabling command injection, rated Critical with a CVSSv3.1 score of 8.9; an official vendor fix has been published.

    00000530
    30.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3485 - Critical A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is ... https://www.thehackerwire.com/vulnerability/CVE-2026-3485/ https://t.co/vZZW726VOn

    Post summary

    A critical OS command injection vulnerability was disclosed in the D-Link DIR-868L’s SSDP Service, affecting function sub_1BF84 via manipulation of the ST argument.

    0000045
    121 followersView on X
  • dbugs@ptdbugs
    PoC

    D-Link DIR-868L SSDP Service sub_1BF84 os command injection CVE: CVE-2026-3485 PT-Identifier: PT-2026-22824 Vendor: D-link Product: DIR-868L CVSS: 9.3 Credits: Xuhsy (VulDB User) Description: A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-3485 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-3485) • https://vuldb.com/?id.348560 -> (https://vuldb.com/?id.348560) • https://vuldb.com/?ctiid.348560 -> (https://vuldb.com/?ctiid.348560) • https://vuldb.com/?submit.764759 -> (https://vuldb.com/?submit.764759) • https://kn0sinna.notion.site/dlink-dir-868l-ssdp-command-injection-30eb1876cd6e80caa691de6fe5cab59c -> (https://kn0sinna.notion.site/dlink-dir-868l-ssdp-command-injection-30eb1876cd6e80caa691de6fe5cab59c) • https://www.dlink.com/ -> (https://www.dlink.com/) #dbugs_vuln

    Post summary

    A new OS command injection vulnerability (CVE-2026-3485) was disclosed for unsupported D‑Link DIR‑868L routers; an exploit has been published, but no active attacks or patch information are reported.

    00000175
    551 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting D-Link DIR-868L (CVE-2026-3485) https://vuldb.com/?ctiid.348560

    Post summary

    CTI team reports widespread activity targeting D-Link DIR-868L CVE-2026-3485, indicating active exploitation in the wild.

    0000064
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3485: CRITICAL] Critical vulnerability discovered in D-Link DIR-868L 110b03, allowing remote OS command injection. Exploit published for non-supported products. #CyberSecurity#cve,CVE-2026-3485,#cybersecurity https://cvefind.com/CVE-2026-3485

    Post summary

    A critical OS command injection vulnerability (CVE-2026-3485) in the D‑Link DIR‑868L 110b03 was disclosed, with an exploit reportedly available but no details on patches or active exploitation.

    0000044
    595 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3485 A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os comma… https://www.cve.org/CVERecord?id=CVE-2026-3485 ----- Traducción: Se ha encontrado … http://infoflow.cloud`

    Post summary

    The post announces the discovery of CVE-2026-3485 in D‑Link DIR‑868L, detailing the affected component and function but offering no proof‑of‑concept, exploit code, or patch information.

    0000030
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3485 A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os comma… https://www.cve.org/CVERecord?id=CVE-2026-3485

    Post summary

    A vulnerability was identified in the SSDP service of the D-Link DIR-868L 110b03, affecting the sub_1BF84 function via manipulation of the ST argument.

    00000235
    56.6K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting D-Link DIR-868L (CVE-2026-3485) https://vuldb.com/?id.348560

    Post summary

    A new vulnerability, CVE-2026-3485, affecting the D-Link DIR-868L router has been added to the vulnerability database.

    0000079
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-868l---
OSdlinkdir-868l_firmware110b03--

Explore more