logo

Patch Now: Dell UnityVSA Flaw Allows Command Execution Without Login

ID: 972d4cce-8b7e-54fc-a540-1b8519ea4b8f

STIX ID: report--972d4cce-8b7e-54fc-a540-1b8519ea4b8f

Feed Name: HackRead

Threat Score
78/100

Date Published: 2025-10-06

Date Updated: 2026-04-22

Author: Waqas

...
...

**Executive summary:** WatchTowr disclosed a pre-authenticated command injection vulnerability (CVE-2025-36604) in Dell UnityVSA that allows unauthenticated remote command execution by injecting shell metacharacters into login redirect URIs; Dell confirms affected versions prior to 5.5.1 and recommends upgrading to 5.5.1+, while WatchTowr published a detection artefact and demonstration video to help defenders validate exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.