6
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Description
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.
Basic Information
ID
CVE-2026-25622
Source
Arista
Published
Jun 5, 2026 at 19:29
Modified
Jun 5, 2026 at 20:26
Affected Product
Vendor
Arista Networks
Product
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Affected Versions
Arista Networks Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) 0