ZeroHour

CVE-2026-81467

large

Unauthenticated OS Command Injection RCE in Dell ThinOS 10

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Dell ThinOS 10, the operating system for Dell Wyse thin clients, contains an OS command injection flaw (CWE-78) in versions prior to 2605_10.2616, where insufficiently sanitized input passed to an operating system command can be abused by an attacker. An unauthenticated attacker with network access to an affected device can send crafted input to the vulnerable interface and achieve arbitrary command execution on the thin client. Successful exploitation carries maximum impact (CVSS 3.1 9.8, scored with high confidentiality, integrity, and availability impact), potentially giving attackers a foothold in enterprise VDI environments. Any organization running Dell Wyse thin clients on ThinOS 10 below 2605_10.2616 is affected, particularly deployments where management or remote-access services on the devices are reachable from untrusted networks. As of now there is no known exploitation, no public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Upgrade affected thin clients to ThinOS 10 version 2605_10.2616 or later. Until patched, restrict network access to thin client management and remote-access services so they are not reachable by unauthenticated or untrusted users. Inventory Wyse deployments for ThinOS 10 versions below 2605_10.2616 and monitor for anomalous inbound connections or unexpected processes on those devices.

Affected
Dell ThinOS 10all versions prior to 2605_10.2616
Estimated exposure
largeon the order of 100,000–1,000,000 deployed Wyse thin clients running ThinOS 10 (internet-exposed subset unknown) — Dell Wyse is a leading enterprise thin client line widely used in VDI fleets, and ThinOS 10 is its current-generation OS, implying hundreds of thousands of devices in enterprise deployments, though most sit on internal networks so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.