Command Injection Vulnerability in Arista Next Generation Firewall
CVE-2026-25622
7HIGH
Key Information:
- Vendor
Arista Networks
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-25622?
A command injection vulnerability has been identified in Arista Edge Threat Management within the Arista Next Generation Firewall. This flaw allows an attacker with administrative access to the user interface to manipulate input handling, enabling them to execute arbitrary shell commands on the affected platform. Proper measures should be taken to secure the environment and limit administrative exposure to mitigate the risk associated with this vulnerability.
Affected Version(s)
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Arista Edge Threat Management - Arista Next Generation Firewall (Formerly Untangle) 0 <= 17.4.0
