CVE-2026-25621: Arista Edge Threat Management NGFW Reports Application Insecure Input Validation
A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely affects version 17.4.0; earlier software releases are not exposed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)to a version that resolves this vulnerability.Fixed in 17.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25621?
The severity of CVE-2026-25621 is classified as medium with a score of 6.
How do I fix CVE-2026-25621?
To fix CVE-2026-25621, upgrade to NGFW Version 17.4.1 as soon as possible.
What kind of input validation issue does CVE-2026-25621 represent?
CVE-2026-25621 represents an insecure input validation issue that can lead to OS command injection.
Which version of the software is affected by CVE-2026-25621?
CVE-2026-25621 uniquely affects version 17.4.0 of Arista Edge Threat Management NGFW.
Is CVE-2026-25621 present in earlier software releases?
No, earlier software releases before version 17.4.0 are not exposed to CVE-2026-25621.