CVE-2026-81467
Dell ThinOS 10 versions before 2605_10.2616 contain a command injection flaw that lets an unauthenticated attacker run arbitrary commands on the device. This could give the attacker full control over the system. The vulnerability is rated critical with a CVSS score of 9.8.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Dell ThinOS 10, versions prior to 2605_10.2616.
Real-world impact
An attacker could execute arbitrary commands on the device, potentially taking full control, exfiltrating data, or disrupting services.
Why this severity
The CVSS score is high because the flaw allows remote, unauthenticated command execution with no user interaction, giving an attacker complete control over confidentiality, integrity, and availability.
What to do about it
- ›Upgrade to a version of Dell ThinOS that is not affected.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources.