VYPR
Unrated severityNVD Advisory· Published Apr 2, 2025· Updated Apr 10, 2025

CVE-2025-27692

CVE-2025-27692

Description

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Wyse Management Suite prior to WMS 5.1 has an unrestricted file upload vulnerability allowing a high-privileged remote attacker to achieve denial of service, information disclosure, or remote code execution.

Vulnerability

CVE-2025-27692 is an Unrestricted Upload of File with Dangerous Type vulnerability in Dell Wyse Management Suite (WMS) versions prior to WMS 5.1 [1]. The flaw resides in proprietary code components where the application does not properly validate or restrict the types of files that can be uploaded by authenticated users. A high-privileged attacker (e.g., an administrator-level user) can upload a malicious file, such as a web shell or executable, to the server. The affected versions are all WMS releases before version 5.1.

Exploitation

To exploit this vulnerability, an attacker needs remote access to the WMS instance and must possess high privileges (e.g., administrator credentials). No user interaction is required beyond the attacker's own actions. The attacker can directly upload a crafted file containing dangerous content (such as a script or binary) to the application's upload endpoint. The server then stores the file and may execute it in the context of the WMS application, depending on the server configuration.

Impact

A successful exploit can lead to multiple severe outcomes: denial of service (by consuming server resources or crashing services), information disclosure (by reading sensitive files or data accessible to the WMS process), and remote code execution (by executing arbitrary commands or binaries on the underlying server). The attacker gains the ability to compromise the confidentiality, integrity, and availability of the WMS system and potentially the managed thin clients.

Mitigation

Dell has addressed this vulnerability in WMS version 5.1. Users should upgrade to WMS 5.1 or later immediately [1]. No workarounds have been published. Administrators should review and restrict file upload permissions and monitor for unusual file activity if upgrading is not immediately possible. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.