← Vulnerability feed

Vulnerability record · CVE-2025-36604 · published 4 August 2025

CVE-2025-36604: Dell Unity OS Command Injection Allows Unauthenticated Remote Code Execution

Dell · Unity Operating Environment

Dell Unity versions 5.5 and prior contain an OS command injection flaw (CWE-78) in the Unity Operating Environment. An unauthenticated remote attacker can inject special elements into an OS command, leading to arbitrary command execution. With a CVSS base score of 9.8 and no authentication or user interaction required, this is a severe pre-auth remote code execution issue.

9.8 CVSS 3.1 Critical EPSS 64% · top 0.8% CWE-78 · OS command injection
9.8CVSS 3.1 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, high EPSS, and public exploit code make this an urgent pre-auth RCE risk.

What it is

Dell Unity versions 5.5 and prior contain an OS command injection flaw (CWE-78) in the Unity Operating Environment. An unauthenticated remote attacker can inject special elements into an OS command, leading to arbitrary command execution. With a CVSS base score of 9.8 and no authentication or user interaction required, this is a severe pre-auth remote code execution issue.

Impact

An attacker gains arbitrary command execution on the affected Dell Unity system, likely with the privileges of the vulnerable service. This can lead to full compromise of the appliance, including data access, configuration changes, and use as a foothold into the network.

Attack surface

The vulnerability is reachable over the network (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), per the CVSS vector. Any remote attacker who can reach the exposed service can attempt exploitation.

Exploitation

The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.63, 99th percentile). Public references include a watchTowr Labs technical write-up and a GitHub proof-of-concept repository, indicating public exploit code and analysis exist.

What to do

  • Apply the Dell security update referenced in DSA-2025-281 for Dell Unity, UnityVSA, and Unity XT as soon as possible.
  • If patching cannot be done immediately, restrict network access to the affected Dell Unity management or service interfaces to trusted hosts only.
  • Monitor vendor advisories for updated fixed versions and any additional mitigation guidance.
  • Segment affected appliances from untrusted networks and limit exposure to the internet.
  • After patching, review logs for signs of prior exploitation and reset credentials if compromise is suspected.

Detection

  • Monitor for unusual child processes spawned by Dell Unity services, especially command shells or system utilities.
  • Inspect network traffic to Dell Unity management interfaces for command injection patterns or anomalous requests.
  • Review system and application logs for unexpected command execution, errors, or service restarts.
  • Use the public watchTowr proof-of-concept to build detection signatures for known exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-36604 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-49601Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 1.5%9.8CVE-2025-22398Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 2.0%9.8CVE-2022-29084Dell unity operating environment improper restriction of authentication attempts vulnerabilityDell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remo…EPSS 1.9%9.1CVE-2025-24383Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 1.1%8.8CVE-2025-24381Dell unity operating environment open redirect vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker wi…EPSS 1.4%7.8CVE-2026-22277Dell unity operating environment os command injection vulnerabilityDell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul…EPSS 0.66%7.8CVE-2026-21418Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vuln…EPSS 0.66%7.8CVE-2025-43942Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2025-36604), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.