Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-26482

Quick assessment

Affected
Dell PowerEdge R770
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dell PowerEdge Server BIOS和Dell iDRAC9都是美国戴尔(Dell)公司的产品。Dell PowerEdge Server BIOS是一款系统更新驱动程序。Dell iDRAC9是提供提供整个的PowerEdge系列服务器全面,嵌入式管理,自动化功能。一个控制器。 Dell PowerEdge Server BIOS和Dell iDRAC9存在安全漏洞,该漏洞源于高权限攻击者可通过远程访问进行攻击,可能导致信息泄露。

CVSS 4.9 · Medium EPSS 0.31% · P21

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-26482

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1258
Source: CVE Program / CVE List V5
Vulnerability Title
Dell PowerEdge Server BIOS和Dell iDRAC9 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Dell PowerEdge Server BIOS和Dell iDRAC9都是美国戴尔(Dell)公司的产品。Dell PowerEdge Server BIOS是一款系统更新驱动程序。Dell iDRAC9是提供提供整个的PowerEdge系列服务器全面,嵌入式管理,自动化功能。一个控制器。 Dell PowerEdge Server BIOS和Dell iDRAC9存在安全漏洞,该漏洞源于高权限攻击者可通过远程访问进行攻击,可能导致信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Dell PowerEdge R770 N/A ~ 1.2.6 -
Dell PowerEdge R670 N/A ~ 1.2.6 -
Dell PowerEdge R570 N/A ~ 1.2.6 -
Dell PowerEdge R470 N/A ~ 1.2.6 -
Dell PowerEdge R6715 N/A ~ 1.1.2 -
Dell PowerEdge R7715 N/A ~ 1.1.2 -
Dell PowerEdge R6725 N/A ~ 1.1.3 -
Dell PowerEdge R7725 N/A ~ 1.1.3 -
Dell PowerEdge R660 N/A ~ 2.5.4 -
Dell PowerEdge R760 N/A ~ 2.5.4 -
Dell PowerEdge C6620 N/A ~ 2.5.4 -
Dell PowerEdge MX760c N/A ~ 2.5.4 -
Dell PowerEdge R860 N/A ~ 2.5.4 -
Dell PowerEdge R960 N/A ~ 2.5.4 -
Dell PowerEdge HS5610 N/A ~ 2.5.4 -
Dell PowerEdge HS5620 N/A ~ 2.5.4 -
Dell PowerEdge R660xs N/A ~ 2.5.4 -
Dell PowerEdge R760xs N/A ~ 2.5.4 -
Dell PowerEdge R760xd2 N/A ~ 2.5.4 -
Dell PowerEdge T560 N/A ~ 2.5.4 -
Dell PowerEdge R760xa N/A ~ 2.5.4 -
Dell PowerEdge XE9680 N/A ~ 2.5.4 -
Dell PowerEdge XE9680L N/A ~ 2.5.4 -
Dell PowerEdge XR5610 N/A ~ 2.5.4 -
Dell PowerEdge XR8610t N/A ~ 2.5.4 -
Dell PowerEdge XR8620t N/A ~ 2.5.4 -
Dell PowerEdge XR7620 N/A ~ 2.5.4 -
Dell PowerEdge XE8640 N/A ~ 2.5.4 -
Dell PowerEdge XE9640 N/A ~ 2.5.4 -
Dell PowerEdge T160 N/A ~ 2.0.0 -

II. Public POCs for CVE-2025-26482

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-26482

请登录查看更多情报信息。

Same Patch Batch · Dell · 2025-09-25 · 6 CVEs total

CVE-2025-43993 7.8 HIGH Dell Wireless 5932e 代码问题漏洞
CVE-2024-48014 7.5 HIGH Dell BSAFE Micro Edition Suite 缓冲区错误漏洞
CVE-2025-43943 6.7 MEDIUM Dell Cloud Disaster Recovery 操作系统命令注入漏洞
CVE-2025-26333 5.9 MEDIUM Dell Crypto-J 安全漏洞
CVE-2025-36601 4.0 MEDIUM Dell PowerScale OneFS 信息泄露漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-26482

No comments yet


Leave a comment