CVE-2026-25624

MEDIUM
5.7CVSS v3
CVSS v2
0.04% EPSS (exploit probability)
CWE-79CWE

Description

An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating vector payload processing behavior controls.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references