Description
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Published: 2026-09-10
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Command execution via OS command injection
Action: Immediate Patch
AI Analysis

Impact

Dell ThinOS 10 firmware versions prior to 2605_10 and 2616 contain a flaw that allows unsafe handling of special characters in OS command strings. The improper neutralization of command elements enables an attacker to inject arbitrary commands, potentially giving them full control over the device's operating system. The description notes that an attacker with high privileges and remote access could exploit the flaw to execute arbitrary commands. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting no known public exploitation yet. Nonetheless, the potential for remote command execution remains a significant threat to any exposed ThinOS device.

Affected Systems

Dell ThinOS 10 devices running firmware older than 2605_10 or 2616 are affected. The vulnerability applies to all editions of ThinOS 10 that have not been updated to the corrected release. No additional vendor or product details were provided in the CVE record.

Risk and Exploitability

The CVSS score of 9.1 signals a high‑severity threat. The lack of an EPSS score indicates no known exploitation at the time of analysis, and its absence from the CISA KEV catalog further supports that it has not been actively exploited publicly. Nevertheless, an attacker with high privileges and remote access could use the command injection vector to execute arbitrary OS commands. Successful exploitation would grant full control over the device, compromising confidentiality, integrity, and availability. The primary attack vector is remote interaction with the ThinOS device over its network interfaces, and the vulnerability can be leveraged by attackers who have obtained or bypassed local credentials, or by those who can directly access the privileged interface via remote management protocols.

Generated by OpenCVE AI on September 10, 2026 at 16:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Dell ThinOS security update released in version 2616 from the official Dell support site (refer to the Dell KB article).
  • Until the update can be applied, disable remote access to the ThinOS device or block the affected command interface using network filtering or firewall rules.
  • Restrict local user privileges on ThinOS to eliminate high‑privileged accounts that could use the injection vector, thereby limiting the impact if the flaw remains unpatched.

Generated by OpenCVE AI on September 10, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Improper Neutralization of OS Command Injection in Dell ThinOS 10

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-10T15:42:41.234Z

Reserved: 2026-08-26T20:04:54.732Z

Link: CVE-2026-81468

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T16:17:58.157

Modified: 2026-09-10T16:17:58.157

Link: CVE-2026-81468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:00:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')