Dell ThinOS 10 版本中,早于 2605_10.2616 的版本存在一个“命令注入”(Command Injection)漏洞,其根本原因是用于命令中的特殊元素未得到妥善中和(Improper Neutralization of Special Elements used in a Command)。 具有相邻网络访问权限的未认证攻击者可能利用此漏洞,进而导致远程代码执行(Remote Code Execution)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81467 | 9.8 CRITICAL | Dell ThinOS 10<2605_10.2616 OS命令注入 |
| CVE-2026-81046 | 9.4 CRITICAL | Dell ThinOS 10.2616前 保护机制失败 |
| CVE-2026-81468 | 9.1 CRITICAL | Dell ThinOS 10远程OS命令注入漏洞 |
| CVE-2026-81052 | 6.8 MEDIUM | Dell ThinOS 10.2616 代码下载无完整性校验 |
| CVE-2026-81051 | 6.6 MEDIUM | Dell ThinOS 10.2616前安全版本号可变漏洞 |
| CVE-2026-81049 | 4.4 MEDIUM | Dell ThinOS 10.2616缺失完整性检查致任意代码执行 |
No comments yet