CVE-2026-25622 - CERT CVE
ID CVE-2026-25622
Sažetak A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.
Reference
CVSS
Base: 6.0
Impact: 4.7
Exploitability:1.2
Pristup
VektorSloženostAutentikacija
NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Zadnje važnije ažuriranje 08-06-2026 - 19:10
Objavljeno 05-06-2026 - 20:17