CVE 6 MEDIUM

Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection_CVE-2026-25622

6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

Description

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.

Basic Information

ID CVE-2026-25622
Source Arista
Published Jun 5, 2026 at 19:29
Modified Jun 5, 2026 at 20:26

Affected Product

Vendor Arista Networks
Product Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Affected Versions Arista Networks Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.