CVE-2026-102162

Summary

On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksWi-Fi Access Points22.0.0 <= 22.0.1F-32affected
Arista NetworksWi-Fi Access Points21.3.0 <= 21.3.0M-13affected
Arista NetworksWi-Fi Access Points1.0.0 < 21.3.0affected

Weaknesses

  • CWE-121: CWE-121 Stack-based Buffer Overflow

Workarounds

If captive portal and application firewall are not required, disabling these features on all SSIDs eliminates exposure to this vulnerability.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References