Junglewise Threat Intelligence

CVE-2026-25624: Arista NGFW administrative XSS in dashboard layout

CVE-2026-25624 · Severity: medium · CVSS 5.7 · Published 2026-06-05

Vendors: Arista Networks.

Executive brief

A security vulnerability exists in the dashboard of Arista's Next Generation Firewall, a device used to protect corporate networks from cyber threats. An attacker with high-level access could inject malicious scripts that execute when an administrator views certain parts of the management interface. This could lead to the unauthorized access of sensitive administrative information or the manipulation of firewall settings.

Technical details

A stored cross-site scripting (XSS) vulnerability exists within the dashboard layout component of the Arista Edge Threat Management (NGFW) web interface. The flaw stems from improper neutralization of user-supplied input (CWE-79), where unvalidated variables are echoed back into administrative profiles. An attacker with high privileges (PR:H) can exploit this over the network by injecting a malicious payload that executes in the context of another administrator's browser session. Successful exploitation requires user interaction (UI:R) and can result in high confidentiality impact, allowing for the theft of session tokens or sensitive configuration data.

Affected products

  • Arista Networks Next Generation Firewall (NGFW) Edge Threat Management

Timeline

  • 2026-06-05: disclosed: Initial publication of the CVE record and Arista advisory.

References