Command Injection in Dell ThinOS 10 before 2605_10.2616
CVE-2026-81048 Published on September 10, 2026
Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution
Vulnerability Analysis
Weakness Type
What is a Command Injection Vulnerability?
The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVE-2026-81048 has been classified to as a Command Injection vulnerability or weakness.
Affected Versions
Dell ThinOS 10:- Before 2605_10.2616 is affected.