CVE-2026-102169: Arista Networks Wi-Fi Access Points

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the captive portal. Remote code execution is not possible.

Affected products

  • Arista Networks Wi-Fi Access Points: from 22.0.0, up to and including 22.0.1F-32; from 21.3.0, up to and including 21.3.0M-13; from 1.0.0, before 21.3.0 (fixed in 21.3.0)

Published 2026-10-06. Last modified 2026-10-07.