THREAT INTELLIGENCE CYBERTTAKv3.0.3.0
LIVE FEED ACTIVE
← Back to Intel Feed
Secure route: /intel/ai-critical-command-injection-vulnerability-in-arista-ng-firewall-cve-2025-6978-125fd3c7
criticalCVE-2025-69782026-02-05Vector: appsec

Critical Command Injection Vulnerability in Arista NG Firewall (CVE-2025-6978)

A security flaw in Arista's NG Firewall could allow an attacker to remotely execute unauthorized commands as a root user. Users are urged to upgrade to version 17.4 or higher to protect their networks.

Decision Context

English Brief

A security flaw in Arista's NG Firewall could allow an attacker to remotely execute unauthorized commands as a root user. Users are urged to upgrade to version 17.4 or higher to protect their networks.

الموجز العربي

ثغرة حقن الأوامر الحرجة في جدار حماية Arista NG (CVE-2025-6978)

تم اكتشاف ثغرة أمنية في جدار حماية Arista NG قد تسمح للمهاجمين بتنفيذ أوامر غير مصرح بها عن بُعد بصلاحيات كاملة. يُنصح المستخدمون بالترقية إلى الإصدار 17.4 أو أعلى لحماية شبكاتهم.

Affected Products
    Priority sectors
    IT and TelecommunicationsNetwork Infrastructure
    Immediate Actions
    1. 1Restrict administrative access to trusted management subnets only.
    2. 2Upgrade Arista NG Firewall to version 17.4 or higher.
    3. 3Monitor /admin/JSON-RPC for suspicious POST requests containing backticks (`) or single quotes (').
    Critical Command Injection Vulnerability in Arista NG Firewall (CVE-2025-6978) | Cyberttak