Command Injection Vulnerability in Dell SmartFabric OS10 Software
CVE-2025-46428

8.8HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
12 November 2025

What is CVE-2025-46428?

The Dell SmartFabric OS10 Software prior to version 10.6.1.0 is susceptible to a command injection vulnerability due to improper neutralization of special elements used in command inputs. This security flaw could allow a low privileged attacker with remote access to execute arbitrary code on an affected system, potentially compromising its integrity and lead to unauthorized operations. It is crucial for users to update their software to the latest version to safeguard against this type of threat. For detailed information and remediation, please refer to Dell's official advisory.

Affected Version(s)

SmartFabric OS10 Software < 10.6.1.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank kkking for reporting these issues.
.
CVE-2025-46428 : Command Injection Vulnerability in Dell SmartFabric OS10 Software