CVE-2026-81048: Command Injection
Dell ThinOS 10, versions prior to 260510.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell ThinOS 10to a version that resolves this vulnerability.Fixed in 2605_10.2616
Event History
Frequently Asked Questions
Which deployments are exposed to exploitation?
Dell ThinOS 10 versions earlier than 2605_10.2616 are affected. Exploitation requires adjacent network access, so the attacker must be on a network segment reachable from the target rather than merely anywhere on the internet.
Does an attacker need credentials or user interaction?
No. The vulnerability is described as exploitable by an unauthenticated attacker, and no user interaction is required.
What is the impact of successful exploitation?
Successful exploitation could lead to remote code execution. The reported severity vector also indicates high confidentiality, integrity, and availability impact.