#VU126176 OS Command Injection in Arista Edge Threat Management - Arista NG Firewall (NGFW) - CVE-2026-25621
Published: April 15, 2026
Arista Edge Threat Management - Arista NG Firewall (NGFW)
Arista Networks
Description
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to improper input validation in the Reports application when importing or restoring a crafted SQL file through the Data tab. A remote privileged user can supply a specially crafted SQL file to execute arbitrary commands.
Exploitation requires use of the Import/Restore Data Backup Files field in the Reports application.