CVE-2026-102167 PUBLISHED

Security Advisory 0197

Assigner: Arista
Reserved: 28.09.2026 Published: 06.10.2026 Updated: 06.10.2026

On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9

Product Status

Vendor Arista Networks
Product Wi-Fi Access Points
Versions Default: unaffected
  • affected from 22.0.0 to 22.0.1F-32 (incl.)
  • affected from 21.3.0 to 21.3.0M-13 (incl.)
  • affected from 1.0.0 to 21.3.0 (excl.)

Affected Configurations

No specific configuration is required beyond default operation. However, exploitation requires the attacker to have access to the access point's wired uplink network.

Workarounds

There is no mitigation or workaround available.

Solutions

CVE-2026-102167 has been fixed in the following releases: - 22.1.1F-61 and later release in the 22.x train - 21.4.0M-12 and later releases in the 21.x train

References

Problem Types

  • CWE-121 Stack-based Buffer Overflow CWE

Impacts

  • CAPEC-100 Overflow Buffers