← Vulnerability feed

Vulnerability record · CVE-2025-45378 · published 5 November 2025

CVE-2025-45378: Dell cloudlink os command injection vulnerability

Dell · Cloudlink

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is possible through network with known privileged user/password.

9.1 CVSS 3.1 Critical EPSS 0.36% · top 73.2% CWE-78 · OS command injection
9.1CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is possible through network with known privileged user/password.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-45378 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34379Dell cloudlink improper authentication vulnerabilityDell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active d…EPSS 1.0%9.1CVE-2021-36312Dell cloudlink hard-coded password vulnerabilityDell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability. A remote high privileged attacker, with the knowledge of t…EPSS 1.1%8.4CVE-2025-45379Dell cloudlink os command injection vulnerabilityDell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to …EPSS 0.67%8.2CVE-2022-34380Dell cloudlink improper authentication vulnerabilityDell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged lo…EPSS 0.20%7.5CVE-2023-28076Dell cloudlink broken cryptographic algorithm vulnerabilityCloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could pote…EPSS 0.42%7.2CVE-2025-46364Dell cloudlink improper privilege management vulnerabilityDell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain…EPSS 0.31%7.2CVE-2025-30479Dell cloudlink os command injection vulnerabilityDell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control …EPSS 1.0%7.2CVE-2024-38482Dell cloudlink vulnerabilityCloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privi…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2025-45378), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.