CVE-2025-6978
published 2025-10-23CVE-2025-6978: Diagnostics command injection vulnerability Diagnostics command injection vulnerability
high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
11.74%
95.5th percentile
Diagnostics command injection vulnerability
Diagnostics command injection vulnerability
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista_networks | arista_edge_threat_management_arista_next_generation_firewall | 0.0 – 17.3.1 | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cvelistv57.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Arista runTroubleshooting HOST Parameter Command Injection Attempt (CVE-2025-6978)
suricata·2026-02-05·CVSS 7.2
CVE-2025-6978 [HIGH] ET WEB_SPECIFIC_APPS Arista runTroubleshooting HOST Parameter Command Injection Attempt (CVE-2025-6978)
ET WEB_SPECIFIC_APPS Arista runTroubleshooting HOST Parameter Command Injection Attempt (CVE-2025-6978)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Arista runTroubleshooting HOST Parameter Command Injection Attempt (CVE-2025-6978)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:15; content:"/admin/JSON-RPC"; http.request_body; content:"|22|method|22|"; content:".runTroubleshooting"; within:100; fast_pattern; content:"|22|params|22 3a 5b 22|DNS|22|"; content:"|22|HOST|22|"; pcre:"/^(?:\x3a(?:\x20\x22|\x22))?[^\x2c\x7d$]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:url,www.zerodayinitiative.com/blog/2026/2/4/cve-2025-6978-arbitrary-code-execution-in-the-arista-ng-firewall; reference:cve,2025
No public exploits indexed.
2025-10-23
Published