CVE-2026-25624
EUVD-2026-3491105.06.2026, 20:17
An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating vector payload processing behavior controls.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| arista | ng_firewall | 𝑥 < 17.4.1 |
𝑥
= Vulnerable software versions