No analysis available yet.
Vendor Solution
The recommended resolution is to upgrade to NGFW Version 17.4.1 at your earliest convenience.
Vendor Workaround
Per operational best practice security models, do not allow unauthorized administrative access to the administrative browser.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands. | |
| Title | Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-06-05T20:26:59.005Z
Reserved: 2026-02-03T22:23:04.359Z
Link: CVE-2026-25622
Updated: 2026-06-05T20:26:55.753Z
Status : Awaiting Analysis
Published: 2026-06-05T20:17:30.820
Modified: 2026-06-05T20:48:41.560
Link: CVE-2026-25622
No data.
OpenCVE Enrichment
No data.