Junglewise Threat Intelligence

CVE-2026-25621: Arista NGFW OS command injection in Reports application

CVE-2026-25621 · Severity: medium · CVSS 6 · Published 2026-06-05

Technologies: Arista Networks Next Generation Firewall. Vendors: Arista Networks.

Executive brief

A security vulnerability exists in the reporting component of Arista Next Generation Firewalls, which are used to secure corporate network perimeters. An attacker with administrative privileges could exploit this flaw to execute unauthorized commands on the system due to improper data handling. This could lead to the theft of sensitive configuration data or partial disruption of the firewall's management functions.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Reports application infrastructure of Arista Edge Threat Management (NGFW). The root cause is insecure input validation of parameters passed to the reporting engine. An attacker with high-privileged (administrative) access can exploit this over the network to execute arbitrary commands on the underlying operating system. While the attack requires authentication, it allows for significant data exfiltration and potential impact on system integrity. This vulnerability is unique to version 17.4.0; earlier versions are reportedly not affected.

Affected products

  • Arista Networks Next Generation Firewall (NGFW) 17.4.0

Timeline

  • 2026-06-05: advisory: Initial advisory published by Arista Networks
  • 2026-06-05: disclosed

References

Related threats