On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts.
Captive portal, or application firewall must be enabled on at least one SSID. If none of these features are configured, the web gateway service does not perform the lookups that expose this vulnerability. Additionally, this can be exploited by an associated client.
If captive portal and application firewall are not required, disabling these features on all SSIDs eliminates exposure to this vulnerability.
CVE-2026-102162 has been fixed in the following releases:
- 22.1.1F-61 and later release in the 22.x train
- 21.4.0M-12 and later releases in the 21.x train