Junglewise Threat Intelligence

CVE-2026-25622: Arista NGFW command injection in Captive Portal Custom Handler

CVE-2026-25622 · Severity: medium · CVSS 6 · Published 2026-06-05

Technologies: Arista Networks Next Generation Firewall. Vendors: Arista Networks.

Executive brief

A security vulnerability has been identified in Arista's Next Generation Firewall, a device used to secure corporate networks and manage user access. An authorized administrator could potentially bypass security controls to run unauthorized commands directly on the device's operating system. While this requires administrative access to exploit, it could allow a malicious insider or a compromised admin account to gain full control over the firewall's underlying system.

Technical details

A command injection vulnerability (CWE-78) exists in the Captive Portal Custom Handler component of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). The flaw stems from improper neutralization of special elements used in OS commands within the user interface's input handling logic. An attacker must have an administrative account and be logged into the web-based management interface to exploit this vulnerability. Successful exploitation allows the execution of arbitrary platform shell commands with the privileges of the web service, potentially leading to full system compromise. Arista has released security advisory 0133 to address this issue.

Affected products

  • Arista Networks Next Generation Firewall (NGFW)

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats