Description
Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution
Published: 2026-09-10
Score: 9.6 Critical
EPSS: 1.3% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a command injection flaw caused by improper neutralization of special elements. An unauthenticated attacker with adjacent network access can inject arbitrary system commands, leading to remote code execution. This compromise affects confidentiality, integrity, and availability and can result in full control over the affected device.

Affected Systems

Dell ThinOS 10 versions prior to 2605_10.2616 are susceptible to this flaw; other vendors or newer releases are not listed as affected.

Risk and Exploitability

The CVSS score of 9.6 indicates a critical severity and the vulnerability is exploitable by unauthenticated users who can reach adjacent networks. The EPSS score is 1%, indicating a low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Its high score and command injection nature mean it is likely to be sought by attackers. Successful exploitation would allow an attacker to execute arbitrary code with the privileges of the ThinOS system, effectively taking control of the device.

Generated by OpenCVE AI on September 11, 2026 at 15:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell ThinOS 10 security update version 2605_10.2616 or later to eliminate the command injection flaw.
  • Restrict adjacent network access by enforcing firewall rules or network segmentation to limit unauthenticated exposure to ThinOS devices.
  • Continuously monitor ThinOS logs for suspicious command execution attempts and apply additional security hardening such as disabling unnecessary services.

Generated by OpenCVE AI on September 11, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in Dell ThinOS 10

Thu, 10 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability Enabling Remote Code Execution on Dell ThinOS 10

Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability Enabling Remote Code Execution on Dell ThinOS 10

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-11T03:56:44.153Z

Reserved: 2026-08-26T15:50:35.362Z

Link: CVE-2026-81048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T16:17:57.543

Modified: 2026-09-11T04:17:57.060

Link: CVE-2026-81048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:00:06Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')