OS Command Injection in Arista Edge Threat Management - Arista NG Firewall (NGFW) - CVE-2026-25620

 

OS Command Injection in Arista Edge Threat Management - Arista NG Firewall (NGFW) - CVE-2026-25620

Published: April 15, 2026


Vulnerability identifier: #VU126175
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25620
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands.

The vulnerability exists due to command injection in the encrypted password handling functionality of the Captive Portal application when processing crafted input in the NGFW user interface. A remote privileged user can submit crafted input to execute arbitrary commands.

Only systems with the Captive Portal application installed and enabled, and with Captive Portal Basic Login enabled, are vulnerable.


Affected software

Arista Edge Threat Management - Arista NG Firewall (NGFW)

How to mitigate CVE-2026-25620

Install security update from vendor's website.

Arista Edge Threat Management - Arista NG Firewall (NGFW) - update to 17.4.1

External References

Related Security Bulletins