CVE-2026-102162: Arista Networks Wi-Fi Access Points

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts.

Affected products

  • Arista Networks Wi-Fi Access Points: from 22.0.0, up to and including 22.0.1F-32; from 21.3.0, up to and including 21.3.0M-13; from 1.0.0, before 21.3.0 (fixed in 21.3.0)

Published 2026-10-06. Last modified 2026-10-07.