CVE-2025-26331: Command Injection
Published Mar 7, 2025
·Updated
Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
Affected Software
13 affected components
Dell ThinOS<2411
All of the following
Dell ThinOS<=2411
Any of the following
Dell Latitude 3420
Dell Latitude 3440
Dell Latitude 5440
Dell Latitude 5450
Dell Optiplex 3000 Thin Client
Dell Optiplex 5400 All-in-one
Dell Optiplex 7410 All-in-one
Dell Optiplex 7420 All-in-one
Dell Wyse 5070 Thin Client
Dell Wyse 5470 All-in-one Thin Client
Dell Wyse 5470 Mobile Thin Client
Event History
Mar 7, 2025
CVE Published
via MITRE·08:06 AM
Data Sourced
via MITRE·08:06 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26331?
CVE-2025-26331 is classified as a low severity vulnerability.
2
How can I mitigate CVE-2025-26331?
To mitigate CVE-2025-26331, ensure that you update to Dell ThinOS versions later than 2411.
3
Who is affected by CVE-2025-26331?
CVE-2025-26331 affects users of Dell ThinOS version 2411 and prior.
4
What type of attack does CVE-2025-26331 allow?
CVE-2025-26331 allows a low privileged attacker with local access to potentially execute arbitrary code.
5
Is remote access required to exploit CVE-2025-26331?
No, a local access point is required to exploit CVE-2025-26331.