CVE-2026-81048 PUBLISHED

Assigner: dell
Reserved: 26.08.2026 Published: 10.09.2026 Updated: 11.09.2026

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor Dell
Product ThinOS 10
Versions Default: unaffected
  • affected from 0 to 2605_10.2616 (excl.)

References

Problem Types

  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE