Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
History

Tue, 01 Jul 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell latitude 3420
Dell latitude 3440
Dell latitude 5440
Dell latitude 5450
Dell optiplex 3000 Thin Client
Dell optiplex 5400 All-in-one
Dell optiplex 7410 All-in-one
Dell optiplex 7420 All-in-one
Dell thinos
Dell wyse 5070 Thin Client
Dell wyse 5470 All-in-one Thin Client
Dell wyse 5470 Mobile Thin Client
CPEs cpe:2.3:h:dell:latitude_3420:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5450:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_3000_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_5400_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_7410_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_7420_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_all-in-one_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_mobile_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:thinos:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell latitude 3420
Dell latitude 3440
Dell latitude 5440
Dell latitude 5450
Dell optiplex 3000 Thin Client
Dell optiplex 5400 All-in-one
Dell optiplex 7410 All-in-one
Dell optiplex 7420 All-in-one
Dell thinos
Dell wyse 5070 Thin Client
Dell wyse 5470 All-in-one Thin Client
Dell wyse 5470 Mobile Thin Client

Fri, 07 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 08:15:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2025-03-11T03:55:16.832Z

Reserved: 2025-02-07T06:04:04.738Z

Link: CVE-2025-26331

cve-icon Vulnrichment

Updated: 2025-03-07T15:19:10.949Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-07T08:15:43.040

Modified: 2025-07-01T15:08:21.283

Link: CVE-2025-26331

cve-icon Redhat

No data.