CVE-2025-26482Network attack vector

Sensitive data disclosure via uncleared debug state

Published Sep 25, 2025 · Updated Sep 26, 2025

Information disclosure in Dell PowerEdge Server BIOS and iDRAC9 allows remote authenticated administrators to read sensitive system data. The firmware leaves security-sensitive values uncleared when debug mode is entered, exposing keys or cryptographic intermediate data. Exploitation requires high privileges and remote access; the reported impact is limited to confidentiality, with no integrity or availability effect.

CVSS severity4.9
Medium
EPSS probability0.31%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Information disclosure in Dell PowerEdge Server BIOS and iDRAC9 allows remote authenticated administrators to read sensitive system data. The firmware leaves security-sensitive values uncleared when debug mode is entered, exposing keys or cryptographic intermediate data. Exploitation requires high privileges and remote access; the reported impact is limited to confidentiality, with no integrity or availability effect.

The record

CVE
CVE-2025-26482
Published
Sep 25, 2025
Updated
Sep 26, 2025
Vendor
Dell
Product
Dell EMC XC Core XCXR2
Classifications
CWE-1258
Attack vector
network
Privileges
admin

Timeline

How it unfolded

  1. Sep 25, 2025CVE publishedPublication date reported by the CVE source.
  2. Sep 26, 2025Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=N/A <2.23.0

What conditions does exploitation require?

Attack vectornetwork
Required privilegesadmin

What is affected?

Dell · Dell EMC XC Core XCXR2version=N/A <2.23.0
Dell · Dell EMC XC Core XC7525version=N/A <2.18.1
Dell · PowerEdge XE9680Lversion=N/A <2.5.4
Dell · PowerEdge R7425version=N/A <1.25.0
Dell · PowerEdge M640version=N/A <2.23.0
Dell · PowerEdge C6620version=N/A <2.5.4
Dell · PowerEdge R6415version=N/A <1.25.0
Dell · Dell EMC XC Core XC750version=N/A <1.16.2
Dell · PowerEdge R6625version=N/A <1.11.2
Dell · Dell EMC XC Core XC750xaversion=N/A <1.16.2
Dell · PowerEdge R7725version=N/A <1.1.3
Dell · PowerEdge R740version=N/A <2.23.0
Dell · PowerEdge R750XAversion=N/A <1.16.2
Dell · PowerEdge C4140version=N/A <2.23.0
Dell · Dell EMC XC Core XC940 Systemversion=N/A <2.23.0
Dell · PowerEdge R960version=N/A <2.5.4
Dell · PowerEdge MX760cversion=N/A <2.5.4
Dell · Dell EMC XC Core XC650version=N/A <1.16.2
Dell · PowerEdge R760xd2version=N/A <2.5.4
Dell · PowerEdge XE8545version=N/A <2.17.1
Dell · Dell XC Core XC760xaversion=N/A <2.5.4
Dell · PowerEdge R360version=N/A <2.0.0
Dell · PowerEdge XR12version=N/A <1.16.2
Dell · PowerEdge R760version=N/A <2.5.4
Dell · PowerEdge C6520version=N/A <1.16.2
Dell · PowerEdge T560version=N/A <2.5.4
Dell · Dell EMC Storage NX3340version=N/A <2.23.0
Dell · PowerEdge R450version=N/A <1.16.2
Dell · PowerEdge R7415version=N/A <1.25.0
Dell · PowerEdge R760xsversion=N/A <2.5.4
Dell · PowerEdge M640 (for PE VRTX)version=N/A <2.23.0
Dell · PowerEdge XR7620version=N/A <2.5.4
Dell · PowerEdge R540version=N/A <2.23.0
Dell · PowerEdge R6725version=N/A <1.1.3
Dell · Dell EMC XC Core XC640 Systemversion=N/A <2.23.0
Dell · PowerEdge XE7420version=N/A <2.23.0
Dell · PowerEdge R350version=N/A <1.11.1
Dell · PowerEdge R940XAversion=N/A <2.23.0
Dell · PowerEdge C6525version=N/A <2.18.1
Dell · PowerEdge R6715version=N/A <1.1.2
Dell · PowerEdge R6515version=N/A <2.18.1
Dell · PowerEdge T440version=N/A <2.23.0
Dell · PowerEdge R250version=N/A <1.11.1
Dell · PowerEdge R7525version=N/A <2.18.1
Dell · Dell XC Core XC7625version=N/A <1.11.2
Dell · PowerEdge XR4520cversion=N/A <1.17.3
Dell · PowerEdge R770version=N/A <1.2.6
Dell · PowerEdge R640version=N/A <2.23.0
Dell · PowerEdge T640version=N/A <2.23.0
Dell · PowerEdge R660xsversion=N/A <2.5.4
Dell · PowerEdge XE8640version=N/A <2.5.4
Dell · PowerEdge T550version=N/A <1.16.2
Dell · PowerEdge C6615version=N/A <1.6.2
Dell · PowerEdge R740xdversion=N/A <2.23.0
Dell · PowerEdge XR2version=N/A <2.23.0
Dell · PowerEdge R650version=N/A <1.16.2
Dell · PowerEdge XE2420version=N/A <2.23.0
Dell · Dell EMC XC Core XC740xd2version=N/A <2.23.0
Dell · PowerEdge MX840cversion=N/A <2.23.0
Dell · Dell XC Core XC760version=N/A <2.5.4
Dell · PowerEdge MX750cversion=N/A <1.16.2
Dell · Dell EMC XC Core XC740xd Systemversion=N/A <2.23.0
Dell · PowerEdge R6525version=N/A <2.18.1
Dell · PowerEdge C6420version=N/A <2.23.0
Dell · PowerEdge R650XSversion=N/A <1.16.2
Dell · PowerEdge HS5620version=N/A <2.5.4
Dell · PowerEdge T160version=N/A <2.0.0
Dell · PowerEdge XE9640version=N/A <2.5.4
Dell · PowerEdge R550version=N/A <1.16.2
Dell · PowerEdge MX740cversion=N/A <2.23.0
Dell · PowerEdge R670version=N/A <1.2.6
Dell · PowerEdge R860version=N/A <2.5.4
Dell · PowerEdge R240version=N/A <2.18.0
Dell · Dell EMC XC Core XC450version=N/A <1.16.2
Dell · PowerEdge XR8610tversion=N/A <2.5.4
Dell · Dell XC Core XC660xsversion=N/A <2.5.4
Dell · PowerEdge R940version=N/A <2.23.0
Dell · PowerEdge HS5610version=N/A <2.5.4
Dell · PowerEdge R7715version=N/A <1.1.2
Dell · PowerEdge R470version=N/A <1.2.6
Dell · PowerEdge R750XSversion=N/A <1.16.2
Dell · PowerEdge XE9680version=N/A <2.5.4
Dell · PowerEdge T360version=N/A <2.0.0
Dell · PowerEdge FC640version=N/A <2.23.0
Dell · PowerEdge T340version=N/A <2.18.0
Dell · PowerEdge XR8620tversion=N/A <2.5.4
Dell · PowerEdge R440version=N/A <2.23.0
Dell · Dell EMC NX440version=N/A <2.18.0
Dell · PowerEdge XR11version=N/A <1.16.2
Dell · Dell EMC XC Core 6420 Systemversion=N/A <2.23.0
Dell · PowerEdge R750version=N/A <1.16.2
Dell · PowerEdge T150version=N/A <1.11.1
Dell · PowerEdge R7615version=N/A <1.11.2
Dell · DSS 8440version=N/A <2.23.0
Dell · Dell XC Core XC660version=N/A <2.5.4
Dell · PowerEdge R760xaversion=N/A <2.5.4
Dell · PowerEdge R660version=N/A <2.5.4
Dell · PowerEdge R6615version=N/A <1.11.2
Dell · PowerEdge XE7440version=N/A <2.23.0
Dell · Dell EMC XC Core XC6520version=N/A <1.16.2
Dell · Dell EMC Storage NX3240version=N/A <2.23.0
Dell · PowerEdge R740xd2version=N/A <2.23.0
Dell · PowerEdge XR5610version=N/A <2.5.4
Dell · PowerEdge T350version=N/A <1.11.1
Dell · Integrated Dell Remote Access Controller 9 (iDRAC9)version=N/A <7.00.00.181; version=N/A <7.20.10.50
Dell · PowerEdge R260version=N/A <2.0.0
Dell · PowerEdge R340version=N/A <2.18.0
Dell · PowerEdge R840version=N/A <2.23.0
Dell · PowerEdge T140version=N/A <2.18.0
Dell · PowerEdge R570version=N/A <1.2.6
Dell · PowerEdge R7515version=N/A <2.18.1
Dell · PowerEdge XR4510cversion=N/A <1.17.3
Dell · PowerEdge R7625version=N/A <1.11.2

Published CVSS scores

4.9DellCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectornetwork
Privilegesadmin
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-1258Exposure of Sensitive System Information Due to Uncleared Debug Information

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo