CVE-2025-6978: Command Injection in Arista NG Firewall

CVE-2025-6978: Command Injection in Arista NG Firewall

First seen 5 Feb 2026, 23:27 UTC ThezdiZerodayinitiative 60.7

Article Content

Browse articles
ThreatCluster

CVE-2025-6978 is a command injection vulnerability in the Arista NG Firewall that allows for arbitrary code execution under the root user context. The vulnerability was discovered by Gereon Huppertz and reported through the TrendAI Zero Day Initiative program. A patch has been released to address this security issue.