ZeroHour

CVE-2026-81048

large

Unauthenticated Command Injection RCE in Dell ThinOS 10

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

Dell ThinOS 10 contains a command injection flaw (CWE-77) caused by improper neutralization of special elements passed into a command, allowing injected commands to run on the underlying thin client. An unauthenticated attacker who has gained adjacent network access — for example, an attacker on the same LAN, Wi-Fi segment, or VLAN as the device — can send crafted input that triggers arbitrary code execution on the appliance. Successful exploitation yields full remote code execution with high impact to confidentiality, integrity, and availability, and the CVSS scope change (S:C) indicates the impact extends beyond the vulnerable component. Any organization running Dell Wyse thin clients on ThinOS 10 versions prior to 2605_10.2616 is affected. There is currently no evidence of active exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Upgrade affected thin clients to Dell ThinOS 2605_10.2616 or later as published in Dell's security advisory. In the interim, segment thin-client networks so untrusted devices cannot reach them at the adjacent/network-adjacent layer, and audit your fleet's ThinOS version to identify devices still running builds below 2605_10.2616.

Affected
Dell ThinOS 10all versions prior to 2605_10.2616
Estimated exposure
largelikely tens of thousands to low hundreds of thousands of ThinOS 10 thin-client endpoints worldwide — Dell Wyse is a leading enterprise thin-client platform with a multi-million-unit cumulative installed base, and ThinOS 10 is the current-generation OS deployed across corporate VDI fleets, so the vulnerable installed base plausibly falls…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution

Weakness
CWE-77
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.