PT-2025-43546 · Unknown · Captive Portal

Published

2025-10-23

·

Updated

2025-11-25

·

CVE-2025-6979

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arista NG Firewall (affected versions not specified)
Description The Captive Portal component contains a flaw that allows authentication bypass. An authenticated user or malicious actor can bypass the authentication process due to improper handling of HTTP responses or configurations. The issue is identified as ZDI-25-1019.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-6979
ZDI-25-1019

Affected Products

Captive Portal