Impact
Dell ThinOS 10 versions before 2605_10 and 2616 contain improper neutralization of special elements used in an OS command, allowing an attacker to inject and execute arbitrary commands. This flaw is classified as OS Command Injection and could compromise confidentiality, integrity, and availability by running malicious code on the device. The vulnerability is triggered when the system interprets untrusted input as part of an operating‑system command line.
Affected Systems
Dell ThinOS 10 devices running release lines 2605_10 or 2616 are affected. Devices with earlier builds are at risk; any newer ThinOS releases should be verified to confirm the absence of this flaw.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. An attacker need only have remote access to the ThinOS service and does not need authentication, making exploitation relatively straightforward. The EPSS score of 4% indicates a moderate exploitation probability. The vulnerability is not listed in CISA KEV, but the high CVSS score, the lack of authentication requirement, and the remote attack surface collectively create a significant risk.
OpenCVE Enrichment