Medium severity6.0NVD Advisory· Published Jun 5, 2026· Updated Jun 8, 2026
CVE-2026-25620
CVE-2026-25620
Description
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.
Affected products
3- cpe:2.3:a:arista:ng_firewall:17.4:*:*:*:*:*:*:*
- Range: =17.4.0
- Range: =17.4.0
Patches
Vulnerability mechanics
References
1- www.arista.com/en/support/advisories-notices/security-advisory/22867-security-advisory-0133nvdVendor AdvisoryMitigation
News mentions
0No linked articles in our index yet.