PT-2026-47045 · Arista · Next Generation Firewall

Published

2026-06-05

·

Updated

2026-06-06

·

CVE-2026-25620

CVSS v3.1

6.0

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) version 17.4.0
Description An encrypted password command injection vulnerability exists in the Captive Portal application framework. Command injection is a flaw that allows an attacker to execute arbitrary operating system commands on the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-25620

Affected Products

Next Generation Firewall