Encrypted Password Command Injection in Arista Next Generation Firewall
CVE-2026-25620
7HIGH
Key Information:
- Vendor
Arista Networks
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-25620?
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Networks' Next Generation Firewall. This specific issue affects version 17.4.0 of the software, while earlier versions do not exhibit this vulnerability. Organizations utilizing this product should take immediate action to review their configurations and update their systems to mitigate potential risks associated with this flaw.
Affected Version(s)
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Arista Edge Threat Management - Arista Next Generation Firewall (Formerly Untangle) 17.4.0
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jon Williams & Ronan Kervella from Bishop Fox
