A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arista ng Firewall
|
|
| CPEs | cpe:2.3:a:arista:ng_firewall:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Arista ng Firewall
|
Sun, 07 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arista
Arista edge Threat Management |
|
| Vendors & Products |
Arista
Arista edge Threat Management |
Fri, 05 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands. | |
| Title | Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Arista
Published: 2026-06-05T19:29:57.126Z
Updated: 2026-06-05T20:26:59.005Z
Reserved: 2026-02-03T22:23:04.359Z
Link: CVE-2026-25622
Updated: 2026-06-05T20:26:55.753Z
Status : Analyzed
Published: 2026-06-05T20:17:30.820
Modified: 2026-06-08T19:10:56.303
Link: CVE-2026-25622
No data.