#VU126178 OS Command Injection in Arista Edge Threat Management - Arista NG Firewall (NGFW) - CVE-2026-25623
Published: April 15, 2026
Arista Edge Threat Management - Arista NG Firewall (NGFW)
Arista Networks
Description
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to command injection in an unspecified command execution functionality when handling crafted input in the NGFW user interface. A remote privileged user can submit crafted input to execute arbitrary commands.
Exploitation requires access to an administrative account logged into the NGFW user interface.