CVE-2025-36579

Physical authentication bypass via weak password recovery

Published Apr 16, 2026 · Updated Apr 16, 2026

Weak password recovery in Dell Client Platform BIOS allows physically proximate attackers to gain unauthorized access without authentication. Dell has not disclosed the recovery routine, stored secret, or validation error that permits the password-recovery mechanism to accept an unauthorized user. Exploitation requires physical access to an affected computer; Dell reports unauthorized access but does not identify the accessible settings or data.

CVSS severity5.1
Medium
EPSS probability0.18%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Weak password recovery in Dell Client Platform BIOS allows physically proximate attackers to gain unauthorized access without authentication. Dell has not disclosed the recovery routine, stored secret, or validation error that permits the password-recovery mechanism to accept an unauthorized user. Exploitation requires physical access to an affected computer; Dell reports unauthorized access but does not identify the accessible settings or data.

The record

CVE
CVE-2025-36579
Published
Apr 16, 2026
Updated
Apr 16, 2026
Vendor
Dell Technologies
Product
Alienware 16X Aurora AC16251
Classifications
CWE-640
Attack vector
physical
Privileges
unauthenticated

Timeline

How it unfolded

  1. Apr 16, 2026CVE publishedPublication date reported by the CVE source.
  2. Apr 16, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <1.8.1

What conditions does exploitation require?

Attack vectorphysical
Required privilegesunauthenticated

What is affected?

Dell Technologies · Alienware 16X Aurora AC16251version=0 <1.8.1
Dell Technologies · Alienware m16 R1version=0 <1.32.0
Dell Technologies · Latitude 3550version=0 <1.20.0
Dell Technologies · Dell Pro Rugged 14 RB14250version=0 <1.12.1
Dell Technologies · Inspiron 16 Plus 7640version=0 <1.22.0
Dell Technologies · Dell Pro Max Slim FCS1250version=0 <1.10.1
Dell Technologies · Dell Pro Slim QCS1255version=0 <1.9.1
Dell Technologies · Inspiron 7710 All-in-Oneversion=0 <1.35.0
Dell Technologies · Latitude 3540version=0 <1.29.0
Dell Technologies · Inspiron 14 5440version=0 <1.19.0
Dell Technologies · XPS 14 (Dell 14 Premium) DA14250version=0 <1.5.1
Dell Technologies · ChengMing 3991version=0 <1.35.1
Dell Technologies · ChengMing 3990version=0 <1.35.1
Dell Technologies · Latitude 3420version=0 <1.46.0
Dell Technologies · Inspiron 27 7730 All-in-Oneversion=0 <1.18.0
Dell Technologies · Dell G15 5510version=0 <1.38.0
Dell Technologies · Dell Pro Max 14 MC14250version=0 <1.9.0
Dell Technologies · XPS 16 (Dell 16 Premium) DA16250version=0 <1.7.0
Dell Technologies · Latitude 3410version=0 <1.36.0
Dell Technologies · Alienware Aurora ACT1250version=0 <1.10.0
Dell Technologies · Dell Pro Max 16 MC16255version=0 <1.6.2
Dell Technologies · Inspiron 5410 All-in-Oneversion=0 <1.35.0
Dell Technologies · Inspiron 16 Plus 7620version=0 <1.34.0
Dell Technologies · Inspiron 16 7630 2-in-1version=0 <1.26.0
Dell Technologies · Inspiron 14 7440 2-in-1version=0 <1.19.0
Dell Technologies · Inspiron 16 Plus 7630version=0 <1.26.0
Dell Technologies · Inspiron 16 5620version=0 <1.33.0
Dell Technologies · Inspiron 14 7430 2-in-1version=0 <1.26.0
Dell Technologies · Dell 14 DC14250version=0 <1.4.0
Dell Technologies · Dell G15 5530version=0 <1.30.0
Dell Technologies · Dell Pro Tower QCT1255version=0 <1.9.1
Dell Technologies · Dell G15 5520version=0 <1.38.0
Dell Technologies · Alienware x16 R1version=0 <1.30.1
Dell Technologies · Inspiron 14 5430version=0 <1.26.0
Dell Technologies · Latitude 3140version=0 <1.28.1
Dell Technologies · Inspiron 5400/5401 All-in-Oneversion=0 <1.37.0
Dell Technologies · Inspiron 7700 All-In-Oneversion=0 <1.37.0
Dell Technologies · Alienware Area-51 AAT2250version=0 <1.11.0
Dell Technologies · Alienware m16 R2version=0 <1.18.0
Dell Technologies · Dell G16 7630version=0 <1.30.0
Dell Technologies · Inspiron 14 7420 2-in-1version=0 <1.31.0
Dell Technologies · Inspiron 3030 Small Desktopversion=0 <1.22.1
Dell Technologies · Inspiron 16 7640 2-in-1version=0 <1.18.0
Dell Technologies · Alienware x14 R2version=0 <1.30.1
Dell Technologies · Inspiron 3910version=0 <1.37.0
Dell Technologies · Alienware m18 R1version=0 <1.32.0
Dell Technologies · Inspiron 3020 Desktopversion=0 <1.32.0
Dell Technologies · Inspiron 5510version=0 <2.39.0
Dell Technologies · Inspiron 24 5420 All-in-Oneversion=0 <1.25.0
Dell Technologies · Dell 16 DC16250version=0 <1.7.0
Dell Technologies · Dell Pro Max Tower T2 FCT2250version=0 <1.10.1
Unity Technologies · Dell Pro Tower Essential QVT1260version=0 <1.10.1
Dell Technologies · Dell Tower ECT1250version=0 <1.10.1
Dell Technologies · Inspiron 14 Plus 7440version=0 <1.22.0
Dell Technologies · Dell Pro Micro QCM1255version=0 <1.9.1
Dell Technologies · Dell Pro 14 Essential PV14250version=0 <1.4.0
Dell Technologies · Dell Pro Slim Essential QVS1260version=0 <1.10.1
Dell Technologies · Latitude 3520version=0 <1.46.0
Dell Technologies · Latitude 3430version=0 <1.32.0
Dell Technologies · Inspiron 3020 Small Desktopversion=0 <1.32.0
Dell Technologies · Dell Pro Max 16 MC16250version=0 <1.9.0
Dell Technologies · Dell Pro Max 14 MC14255version=0 <1.6.2
Dell Technologies · Latitude 3340version=0 <1.29.0
Dell Technologies · Inspiron 16 7620 2-in-1version=0 <1.31.0
Dell Technologies · Inspiron 16 5640version=0 <1.18.0
Dell Technologies · Latitude 3320version=0 <1.41.0
Dell Technologies · Alienware m18 R2version=0 <1.20.0
Dell Technologies · Dell Pro Laptop PC14250version=0 <1.10.2
Dell Technologies · Latitude 3450version=0 <1.20.0
Dell Technologies · Dell Pro 13 Plus PB13255version=0 <1.9.1
Dell Technologies · Dell Pro 16 Plus PB16255version=0 <1.9.1
Dell Technologies · ChengMing 3900version=0 <1.37.0
Dell Technologies · Dell Pro 14 PC14250version=0 <1.10.2
Dell Technologies · Inspiron 3030 Desktopversion=0 <1.22.1
Dell Technologies · Alienware x16 R2version=0 <1.18.1
Dell Technologies · Alienware 18 Area-51 AA18250version=0 <1.9.0
Dell Technologies · Inspiron 16 5630version=0 <1.26.0
Dell Technologies · Dell G15 5511version=0 <1.41.0
Dell Technologies · Latitude 3510version=0 <1.36.0
Dell Technologies · Inspiron 14 Plus 7430version=0 <1.26.0
Dell Technologies · Latitude 3330version=0 <1.33.0
Dell Technologies · Dell Slim ECS1250version=0 <1.10.1
Dell Technologies · Dell G16 7620version=0 <1.38.0
Dell Technologies · Dell Pro 13 Premium PA13250version=0 <2.8.1
Dell Technologies · Dell Pro 14 Premium PA14250version=0 <2.8.1
Dell Technologies · Latitude 3140 2-in-1version=0 <1.28.1
Dell Technologies · Latitude 3120version=0 <1.35.1
Dell Technologies · Inspiron 13 5320version=0 <1.30.0
Dell Technologies · Inspiron 14 5420version=0 <1.33.0
Dell Technologies · Inspiron 24 5430 All-in-Oneversion=0 <1.18.0
Dell Technologies · Alienware m15 R7version=0 <1.37.0
Dell Technologies · Inspiron 13 5330version=0 <1.28.0
Dell Technologies · Dell Pro Rugged 13 RA13250version=0 <1.12.1
Dell Technologies · ChengMing 3910/3911version=0 <1.32.0
Dell Technologies · Alienware 16 Area-51 AA16250version=0 <1.9.0
Dell Technologies · Dell 16 DC16251version=0 <1.7.0
Dell Technologies · Latitude 3530version=0 <1.32.0
Dell Technologies · Inspiron 14 Plus 7420version=0 <1.34.0
Dell Technologies · Dell Pro 16 Plus PB16250version=0 <2.8.1
Dell Technologies · Dell Pro 13 Plus PB13250version=0 <2.8.1
Dell Technologies · Inspiron 15 3511version=0 <1.43.0
Dell Technologies · Dell 15 DC15250version=0 <1.6.0
Dell Technologies · Inspiron 5401 AIOversion=0 <1.37.0
Dell Technologies · Dell G5 5000version=0 <1.28.2
Dell Technologies · Latitude 3440version=0 <1.29.0
Dell Technologies · Dell Tower Plus EBT2250version=0 <1.11.0
Dell Technologies · Inspiron 27 7720 All-in-Oneversion=0 <1.25.0
Dell Technologies · Dell Pro 16 PC16250version=0 <1.10.2
Dell Technologies · Inspiron 16 7610version=0 <1.36.0
Dell Technologies · Inspiron 15 3520version=0 <1.39.0
Dell Technologies · Dell Pro Max Micro FCM2250version=0 <1.10.1
Dell Technologies · Dell Pro 14 Plus PB14250version=0 <2.8.1
Dell Technologies · Dell Pro 15 Essential PV15250version=0 <1.2.0
Dell Technologies · Alienware m15 R6version=0 <1.42.0
Dell Technologies · Dell Pro 14 Plus PB14255version=0 <1.9.1

Published CVSS scores

5.1Dell TechnologiesCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorphysical
Privilegesunauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-640Weak Password Recovery Mechanism for Forgotten Password

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo