CVE-2026-102162 PUBLISHED

Security Advisory 0193

Assigner: Arista
Reserved: 28.09.2026 Published: 06.10.2026 Updated: 06.10.2026

On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor Arista Networks
Product Wi-Fi Access Points
Versions Default: unaffected
  • affected from 22.0.0 to 22.0.1F-32 (incl.)
  • affected from 21.3.0 to 21.3.0M-13 (incl.)
  • affected from 1.0.0 to 21.3.0 (excl.)

Affected Configurations

Captive portal, or application firewall must be enabled on at least one SSID. If none of these features are configured, the web gateway service does not perform the lookups that expose this vulnerability. Additionally, this can be exploited by an associated client.

Workarounds

If captive portal and application firewall are not required, disabling these features on all SSIDs eliminates exposure to this vulnerability.

Solutions

CVE-2026-102162 has been fixed in the following releases: - 22.1.1F-61 and later release in the 22.x train - 21.4.0M-12 and later releases in the 21.x train

References

Problem Types

  • CWE-121 Stack-based Buffer Overflow CWE

Impacts

  • CAPEC-100 Overflow Buffers