CVE-2026-102163: Arista Networks Wi-Fi Access Points

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless association or authentication is required.

Affected products

  • Arista Networks Wi-Fi Access Points: from 22.0.0, up to and including 22.0.1F-32; from 21.3.0, up to and including 21.3.0M-13; from 1.0.0, before 21.3.0 (fixed in 21.3.0)

Published 2026-10-06. Last modified 2026-10-07.