Description
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution.
Published: 2026-09-10
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

Dell ThinOS 10 versions prior to 2605_10.2616 contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker who has physical access may exploit this flaw, leading to arbitrary code execution on the affected device. The weakness (CWE‑494) permits execution of malicious code without verifying its integrity, compromising confidentiality, integrity, and availability of the system.

Affected Systems

Dell ThinOS 10, versions before 2605_10.2616

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. EPSS data is not available, so the current exploitation probability is uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploitation yet. Because the attack requires physical access and unauthenticated use, the primary vector is local; attackers would need to physically hand a removable medium or similar to trigger the download and execution.

Generated by OpenCVE AI on September 10, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell ThinOS 10 security update that resolves the download integrity issue, upgrading to version 2605_10.2616 or later.
  • Limit physical access to ThinOS devices to authorized personnel to prevent unauthenticated attackers from inserting malicious code or restrict the ability to download executable code without integrity checks and enforce proper code verification procedures.
  • Disable execution of code from removable media and enforce code signing verification or use a trusted package source to ensure only authenticated binaries can run.

Generated by OpenCVE AI on September 10, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Allows Arbitrary Code Execution via Download of10

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution.
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-10T15:32:32.948Z

Reserved: 2026-08-26T15:50:35.363Z

Link: CVE-2026-81052

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T16:17:57.920

Modified: 2026-09-10T16:17:57.920

Link: CVE-2026-81052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:30:10Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check