CVE-2026-25622: Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25622?
The severity of CVE-2026-25622 is rated as medium, with a score of 6.
How do I fix CVE-2026-25622?
To fix CVE-2026-25622, upgrade to NGFW Version 17.4.1 at your earliest convenience.
What type of vulnerability is represented by CVE-2026-25622?
CVE-2026-25622 represents an OS Command Injection vulnerability in Arista Edge Threat Management.
Who is affected by CVE-2026-25622?
CVE-2026-25622 affects users of the Arista Next Generation Firewall with certain administrative access privileges.
What can attackers achieve using CVE-2026-25622?
Attackers can exploit CVE-2026-25622 to execute arbitrary commands on the platform due to improper input handling.