Impact
The vulnerability is a command injection flaw caused by improper neutralization of special elements. An unauthenticated attacker with adjacent network access can inject arbitrary system commands, leading to remote code execution. This compromise affects confidentiality, integrity, and availability and can result in full control over the affected device.
Affected Systems
Dell ThinOS 10 versions prior to 2605_10.2616 are susceptible to this flaw; other vendors or newer releases are not listed as affected.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity and the vulnerability is exploitable by unauthenticated users who can reach adjacent networks. The EPSS score is 1%, indicating a low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Its high score and command injection nature mean it is likely to be sought by attackers. Successful exploitation would allow an attacker to execute arbitrary code with the privileges of the ThinOS system, effectively taking control of the device.
OpenCVE Enrichment