CVE-2026-102164: Arista Networks Wi-Fi Access Points
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible.
Affected products
- Arista Networks Wi-Fi Access Points: from 22.0.0, up to and including 22.0.1F-32; from 21.3.0, up to and including 21.3.0M-13; from 1.0.0, before 21.3.0 (fixed in 21.3.0)
Published 2026-10-06. Last modified 2026-10-07.