CVE-2026-25623
Command Execution in Arista NGFW Browser Management
Publication date: 2026-06-05
Last updated on: 2026-06-05
Assigner: Arista Networks, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| arista | next_generation_firewall | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an input validation command execution flaw found in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW).
It allows authenticated administrators to exploit the issue to gain permissions to execute underlying terminal script code processing.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing authenticated administrators to execute terminal scripts that they might not normally have permission to run.
This could lead to unauthorized command execution, potentially compromising the integrity, confidentiality, and availability of the affected system.