Back to CVE List

CVE-2026-25622

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

Vulnerability Description

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-78
Source
NVD
Vendor
Arista Networks
Product
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)

External References

Discussion (0)

Add Comment

No comments yet. Be the first!