← Back

CVE-2025-26331

nvd nist
Published: Mar 7, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: security_alert@emc.com (Secondary)

Description

Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

Affected (1)

Products: Dell: Thinos
1 product
Thinos
Configuration A
1 vulnerable · 11 platform
Vulnerable SoftwareAffected Versions
Up to 2411
Running on/withPlatform Versions
Dell
Latitude 3420
All versions
Dell
Latitude 3440
All versions
Dell
Latitude 5440
All versions
Dell
Latitude 5450
All versions
Dell
Optiplex 3000 Thin Client
All versions
Dell
Optiplex 5400 All In One
All versions
Dell
Optiplex 7410 All In One
All versions
Dell
Optiplex 7420 All In One
All versions
Dell
Wyse 5070 Thin Client
All versions
Dell
Wyse 5470 All In One Thin Client
All versions
Dell
Wyse 5470 Mobile Thin Client
All versions

References (2)

Source: security_alert@emc.com
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party Advisory

Timeline

No history available yet.