Command Execution Vulnerability in Arista Next Generation Firewall
CVE-2026-25623
7HIGH
Key Information:
- Vendor
Arista Networks
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-25623?
An input validation vulnerability allows authenticated administrators in Arista's Edge Threat Management systems to execute terminal script code. This exposure can lead to unauthorized access to critical functionalities, enabling potentially harmful commands to be processed. Proper input validation measures are essential to mitigate this risk.
Affected Version(s)
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Arista Edge Threat Management - Arista Next Generation Firewall (Formerly Untangle) 0 <= 17.4.0
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jon Williams & Ronan Kervella from Bishop Fox
