On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.
No specific configuration is required beyond default operation. However, exploitation requires the attacker to have access to the access point's wired uplink network.
There is no mitigation or workaround available.
CVE-2026-102167 has been fixed in the following releases:
- 22.1.1F-61 and later release in the 22.x train
- 21.4.0M-12 and later releases in the 21.x train