CVE-2026-102165: Arista Networks Wi-Fi Access Points
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode.
Affected products
- Arista Networks Wi-Fi Access Points: from 22.0.0, up to and including 22.0.1F-32; from 21.3.0, up to and including 21.3.0M-13; from 1.0.0, before 21.3.0 (fixed in 21.3.0)
Published 2026-10-06. Last modified 2026-10-07.