Command Injection Vulnerability in Arista Next Generation Firewall
CVE-2026-25622

7HIGH

What is CVE-2026-25622?

A command injection vulnerability has been identified in Arista Edge Threat Management within the Arista Next Generation Firewall. This flaw allows an attacker with administrative access to the user interface to manipulate input handling, enabling them to execute arbitrary shell commands on the affected platform. Proper measures should be taken to secure the environment and limit administrative exposure to mitigate the risk associated with this vulnerability.

Affected Version(s)

Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Arista Edge Threat Management - Arista Next Generation Firewall (Formerly Untangle) 0 <= 17.4.0

References

EPSS Score

9% chance of being exploited in the next 30 days.

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jon Williams & Ronan Kervella from Bishop Fox
.