Stack Overflow Vulnerability in Arista Wi-Fi Access Points with Captive Portal
CVE-2026-102162
What is CVE-2026-102162?
A vulnerability exists in the wireless gateway service of Arista Wi-Fi access points with the captive portal functionality or application firewall enabled for one or more SSIDs. This issue allows an unauthenticated, network-adjacent attacker to exploit the device by sending specially crafted packets, which may lead to a stack overflow. The resulting impact can include denial-of-service conditions or the potential for arbitrary code execution on the affected device. Notably, the wireless gateway service is automatically restarted after a crash, creating opportunities for repeated attacks.
Affected Version(s)
Wi-Fi Access Points Wi-Fi Access Points 22.0.0 <= 22.0.1F-32
Wi-Fi Access Points Wi-Fi Access Points 21.3.0 <= 21.3.0M-13
Wi-Fi Access Points Wi-Fi Access Points 1.0.0 < 21.3.0
