CVE-2025-26331

Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:thinos:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:latitude_3420:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5450:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_3000_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_5400_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_7410_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_7420_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_all-in-one_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_mobile_thin_client:-:*:*:*:*:*:*:*

History

01 Jul 2025, 15:08

Type Values Removed Values Added
First Time Dell latitude 5450
Dell
Dell wyse 5470 Mobile Thin Client
Dell wyse 5070 Thin Client
Dell latitude 3440
Dell optiplex 7420 All-in-one
Dell optiplex 3000 Thin Client
Dell latitude 5440
Dell optiplex 7410 All-in-one
Dell latitude 3420
Dell optiplex 5400 All-in-one
Dell wyse 5470 All-in-one Thin Client
Dell thinos
CPE cpe:2.3:h:dell:wyse_5470_mobile_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_5400_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5450:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_7410_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_all-in-one_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:thinos:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_3000_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_7420_all-in-one:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3420:-:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000289886/dsa-2025-107 - () https://www.dell.com/support/kbdoc/en-us/000289886/dsa-2025-107 - Vendor Advisory
References () https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2025-26331 - () https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2025-26331 - Third Party Advisory

07 Mar 2025, 16:15

Type Values Removed Values Added
References
  • () https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2025-26331 -
Summary
  • (es) Dell ThinOS 2411 y versiones anteriores contienen una vulnerabilidad de neutralización inadecuada de elementos especiales utilizados en un comando ('inyección de comando'). Un atacante con pocos privilegios y acceso local podría aprovechar esta vulnerabilidad, lo que provocaría la ejecución de código arbitrario.

07 Mar 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-07 08:15

Updated : 2025-07-01 15:08


NVD link : CVE-2025-26331

Mitre link : CVE-2025-26331

CVE.ORG link : CVE-2025-26331


JSON object : View

Products Affected

dell

  • optiplex_5400_all-in-one
  • optiplex_7420_all-in-one
  • wyse_5470_mobile_thin_client
  • optiplex_7410_all-in-one
  • wyse_5470_all-in-one_thin_client
  • wyse_5070_thin_client
  • optiplex_3000_thin_client
  • latitude_5450
  • latitude_5440
  • thinos
  • latitude_3420
  • latitude_3440
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')