Encrypted Password Command Injection in Arista Next Generation Firewall
CVE-2026-25620

7HIGH

What is CVE-2026-25620?

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Networks' Next Generation Firewall. This specific issue affects version 17.4.0 of the software, while earlier versions do not exhibit this vulnerability. Organizations utilizing this product should take immediate action to review their configurations and update their systems to mitigate potential risks associated with this flaw.

Affected Version(s)

Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) Arista Edge Threat Management - Arista Next Generation Firewall (Formerly Untangle) 17.4.0

References

EPSS Score

9% chance of being exploited in the next 30 days.

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jon Williams & Ronan Kervella from Bishop Fox
.