Description
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.
Published: 2026-06-05
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Command Injection
Action: Patch Now
AI Analysis

Impact

The encrypted password command injection flaw exists within the Captive Portal framework of Arista Edge Threat Management NGFW. An attacker who can influence the password handling logic can inject arbitrary system commands, leading to potential remote code execution or unintended configuration changes. This weakness is classified as CWE-78 and can compromise the integrity and availability of the firewall.

Affected Systems

The flaw only affects Arista Edge Threat Management – Arista Next Generation Firewall (NGFW) version 17.4.0; all earlier releases remain unaffected. The vulnerability exists specifically in the Captive Portal configuration component of the NGFW.

Risk and Exploitability

The CVSS score of 7 indicates moderate to high severity, while the EPSS score of less than 1% points to a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be network‑based, targeting the Captive Portal configuration interface that is typically reachable only from trusted administrative networks. If exploited, it could allow an attacker to execute arbitrary commands on the device.

Generated by OpenCVE AI on September 24, 2026 at 19:41 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to NGFW Version 17.4.1 at your earliest convenience.


Vendor Workaround

If managing an active NGFW 17.4.0 deployment, disable the Captive Portal Basic Login configuration profile parameter.


OpenCVE Recommended Actions

  • Upgrade the NGFW to version 17.4.1 as soon as possible.
  • Disable the Captive Portal Basic Login configuration profile parameter if an upgrade cannot be performed immediately.
  • Restrict access to the Captive Portal configuration interface to trusted administrators only.
  • Monitor logs for anomalous command activity and apply any additional patches when available.

Generated by OpenCVE AI on September 24, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 08 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Arista ng Firewall
CPEs cpe:2.3:a:arista:ng_firewall:17.4:*:*:*:*:*:*:*
Vendors & Products Arista ng Firewall

Sun, 07 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista edge Threat Management
Vendors & Products Arista
Arista edge Threat Management

Fri, 05 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.
Title Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/S:P'}


Subscriptions

Arista Edge Threat Management Ng Firewall
cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-06-05T20:23:31.151Z

Reserved: 2026-02-03T22:23:04.359Z

Link: CVE-2026-25620

cve-icon Vulnrichment

Updated: 2026-06-05T20:23:28.256Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-05T20:17:30.447

Modified: 2026-07-23T07:10:00.113

Link: CVE-2026-25620

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T19:45:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')