Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements
Dell ThinOS 10 has a flaw that could let an unauthenticated attacker run commands remotely. The attacker must have access to the same nearby network.
- Severity
- CriticalCVSS 3.1 · 9.6
- Fix
- Not confirmedLast checked yesterday
- Affected versions
- before 2605_10.2616
- Weakness
- CWE-77Command Injection
- Exploit likelihood
- 1.3% in 30 daysEPSS, higher than 69% of known flaws
- Affects
- ThinOS 10
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: total
- EU ID
- EUVD-2026-75561ENISA vulnerability database
How it works
- The advisory identifies this as command injection.
- An unauthenticated attacker with adjacent network access could potentially exploit it.
- Successful exploitation could lead to remote code execution.
- The supplied evidence does not describe the input, entry point, or processing step.
What to do
Check the ThinOS 10 version on each device and compare it with 2605_10.2616. Versions below that release are affected.
Install ThinOS 10 version 2605_10.2616 or later using Dell's security advisory.
Technical details
CVE-2026-81048 is a command injection issue with a CVSS score of 9.6. It requires no authentication or user interaction, but exploitation requires adjacent network access and could affect confidentiality, integrity, and availability.
Severity breakdown
- Attack vector Adjacent Needs access to the same local network
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- tenable.com · CVE-2026-81048 third party advisory vdb entry
- cve.org · CVERecord vdb entry
- cvefeed.io · CVE-2026-81048 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-81048
- dell.com · dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities vendor-advisory NVD