Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection
CVE-2026-25622
7HIGH
Key Information:
- Vendor
Arista Networks
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-25622?
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.
Affected Version(s)
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Arista Edge Threat Management - Arista Next Generation Firewall (Formerly Untangle) 0 <= 17.4.0
