← Back to CVE search

CVE-2026-25622

Arista Edge Threat Management

Description

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.

CVSS 6EPSS 9.879999999999999%Risk 1.13
View source
Published
2026-06-05 20:17:30
Affected versions
unknown
Type
Core software
Last modified
2026-07-23 07:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L