Patch Now: Dell UnityVSA Flaw Allows Command Execution Without Login
ID: 972d4cce-8b7e-54fc-a540-1b8519ea4b8f
STIX ID: report--972d4cce-8b7e-54fc-a540-1b8519ea4b8f
Feed Name: HackRead
Threat Score
**Executive summary:** WatchTowr disclosed a pre-authenticated command injection vulnerability (CVE-2025-36604) in Dell UnityVSA that allows unauthenticated remote command execution by injecting shell metacharacters into login redirect URIs; Dell confirms affected versions prior to 5.5.1 and recommends upgrading to 5.5.1+, while WatchTowr published a detection artefact and demonstration video to help defenders validate exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
