Cross-Site Scripting Vulnerability in Arista Next Generation Firewall
CVE-2026-25624
Key Information:
- Vendor
Arista Networks
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-25624?
An administrative cross-site scripting vulnerability has been identified within the web user interface dashboard of Arista Edge Threat Management - Arista Next Generation Firewall. This issue arises when unvalidated user-supplied variables are returned to administrative profiles, allowing attackers to exploit these inputs and potentially manipulate the behavior of the application. Ensuring adequate input validation and sanitization measures is crucial for maintaining the integrity and security of the administrative user interface.
Affected Version(s)
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Arista Edge Threat Management - Arista Next Generation Firewall (Formerly Untangle) 0 <= 17.4.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
