216.73.217.22

CVE-2026-25620

· Published 05/06/2026 20:17 · Modified 05/06/2026 20:48

Labels: CVE-2026-25620 2026-06-05CVE-2026-25620CWE-78[email protected]

Essential information

Published
05/06/2026 20:17
Modified
05/06/2026 20:48
Author
Creator
CVSS
7.0 HIGH (v3) 7.0 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
arista / next generation firewall cpe:2.3:a:arista:next_generation_firewall:17.4.0:*:*:*:*:*:*:*

References