Stack Overflow Vulnerability in Arista Wi-Fi Access Points with Captive Portal
CVE-2026-102162

9.4CRITICAL

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-102162?

A vulnerability exists in the wireless gateway service of Arista Wi-Fi access points with the captive portal functionality or application firewall enabled for one or more SSIDs. This issue allows an unauthenticated, network-adjacent attacker to exploit the device by sending specially crafted packets, which may lead to a stack overflow. The resulting impact can include denial-of-service conditions or the potential for arbitrary code execution on the affected device. Notably, the wireless gateway service is automatically restarted after a crash, creating opportunities for repeated attacks.

Affected Version(s)

Wi-Fi Access Points Wi-Fi Access Points 22.0.0 <= 22.0.1F-32

Wi-Fi Access Points Wi-Fi Access Points 21.3.0 <= 21.3.0M-13

Wi-Fi Access Points Wi-Fi Access Points 1.0.0 < 21.3.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.