← Back to CVE List
CVE-2026-102162NVD
Vulnerability Summary
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts.
CVSS v4.0 Base Metrics — Score 9.4 (CRITICAL)
Attack VectorAdjacent
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)High
Integrity (Subsequent System)High
Availability (Subsequent System)High
CVSS v3.1 Base Metrics — Score 8.8 (HIGH)
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Arista Networks Wi-Fi Access Points >= 22.0.0 and <= 22.0.1F-32
- Arista Networks Wi-Fi Access Points >= 21.3.0 and <= 21.3.0M-13
- Arista Networks Wi-Fi Access Points >= 1.0.0 and < 21.3.0
- Arista Networks Wi-Fi Access Points 22.0.1F-32
- Arista Networks Wi-Fi Access Points 21.3.0M-13
- Arista Networks Wi-Fi Access Points 21.3.0