CVE-2026-81048
largeUnauthenticated Command Injection RCE in Dell ThinOS 10
Dell ThinOS 10 contains a command injection flaw (CWE-77) caused by improper neutralization of special elements passed into a command, allowing injected commands to run on the underlying thin client. An unauthenticated attacker who has gained adjacent network access — for example, an attacker on the same LAN, Wi-Fi segment, or VLAN as the device — can send crafted input that triggers arbitrary code execution on the appliance. Successful exploitation yields full remote code execution with high impact to confidentiality, integrity, and availability, and the CVSS scope change (S:C) indicates the impact extends beyond the vulnerable component. Any organization running Dell Wyse thin clients on ThinOS 10 versions prior to 2605_10.2616 is affected. There is currently no evidence of active exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Upgrade affected thin clients to Dell ThinOS 2605_10.2616 or later as published in Dell's security advisory. In the interim, segment thin-client networks so untrusted devices cannot reach them at the adjacent/network-adjacent layer, and audit your fleet's ThinOS version to identify devices still running builds below 2605_10.2616.
| Dell ThinOS 10 | all versions prior to 2605_10.2616 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.