Impact
Dell ThinOS 10 versions to 2605_10 and 2616 contain a flaw that allows unsafe handling of special characters in OS command strings. The improper neutralization of command elements (CWE-78) enables an attacker to inject arbitrary commands, potentially giving them full control over the device's operating system. The description notes that exploitation of the flaw can execute arbitrary commands. An EPSS score of 2% is available, and the issue is not listed in the public exploitation yet. Nonetheless, the potential for remote command execution remains a significant threat to any exposed ThinOS device.
Affected Systems
Dell ThinOS 10 devices with firmware versions that are older than the corrected releases (the CVE description references versions prior to 2605_10. 2616). The affected firmware versions have not been updated to the fixes listed in the Dell support KB article 000502746. No additional vendor or product details were provided in the CVE record.
Risk and Exploitability
The CVSS score of 9.1 signals a high‑severity threat. The EPSS score of 2% indicates a modest probability of exploitation, and its absence from the CISA KEV catalog further supports that it has not been actively exploited publicly. Nevertheless, an attacker with high privileges and remote access could use the command injection vector to execute arbitrary OS commands. Successful exploitation would grant full control over the device, compromising confidentiality, integrity, and availability. The primary attack vector is remote interaction with the ThinOS device over its network interfaces, and the vulnerability can be leveraged by attackers who have obtained or bypassed local credentials, or by those who can directly access the privileged interface via remote management protocols.
OpenCVE Enrichment