CVE-2026-25622
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
6.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Vulnerability Description
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-78
Source
NVD
Vendor
Arista Networks
Product
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Discussion (0)
Add Comment
No comments yet. Be the first!