CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 400

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall

A command injection vulnerability (CVE-2025-6978) was discovered in the Arista NG Firewall through improper validation of user input in the diagnostics component, allowing authenticated attackers to achieve arbitrary code execution with root privileges. The flaw exists in the JSON-RPC endpoint's runTroubleshooting() method, which fails to properly sanitize parameters before using them in command-line operations. The vulnerability has been patched following disclosure through the TrendAI Zero Day Initiative program.

Why it matters: Root-level command execution on firewall appliances requires immediate patching to prevent compromise of network perimeter security and potential lateral movement within protected environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall

A command injection vulnerability (CVE-2025-6978) was discovered in the Arista NG Firewall through improper validation of user input in the diagnostics component, allowing authenticated attackers to achieve arbitrary code execution with root privileges. The flaw exists in the JSON-RPC endpoint's runTroubleshooting() method, which fails to properly sanitize parameters before using them in command-line operations. The vulnerability has been patched following disclosure through the TrendAI Zero Day Initiative program.

Why it matters: Root-level command execution on firewall appliances requires immediate patching to prevent compromise of network perimeter security and potential lateral movement within protected environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary