CVE-2026-25620

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:arista:ng_firewall:17.4:*:*:*:*:*:*:*

History

23 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección de comandos de contraseña cifrada existe en el framework de la aplicación Captive Portal de Arista Edge Threat Management - Arista Cortafuegos de Próxima Generación (NGFW). Este problema afecta únicamente a la versión 17.4.0; las versiones de software anteriores no están expuestas.

17 Jun 2026, 10:24

Type Values Removed Values Added
References () https://www.arista.com/en/support/advisories-notices/security-advisory/22867-security-advisory-0133 - Vendor Advisory, Mitigation () https://www.arista.com/en/support/advisories-notices/security-advisory/22867-security-advisory-0133 - Mitigation, Vendor Advisory

08 Jun 2026, 19:15

Type Values Removed Values Added
First Time Arista ng Firewall
Arista
References () https://www.arista.com/en/support/advisories-notices/security-advisory/22867-security-advisory-0133 - () https://www.arista.com/en/support/advisories-notices/security-advisory/22867-security-advisory-0133 - Vendor Advisory, Mitigation
CPE cpe:2.3:a:arista:ng_firewall:17.4:*:*:*:*:*:*:*

05 Jun 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-05 20:17

Updated : 2026-07-23 07:10


NVD link : CVE-2026-25620

Mitre link : CVE-2026-25620

CVE.ORG link : CVE-2026-25620


JSON object : View

Products Affected

arista

  • ng_firewall
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')