Remote Code Execution Vulnerability in Arista Wi-Fi Access Points
CVE-2026-102165

7.7HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-102165?

An unauthenticated attacker with network access to affected Arista Wi-Fi access points can exploit a vulnerability in the capture service by sending a specially crafted packet. This can lead to a service crash or remote code execution, particularly when an uncommon non-default streaming mode is used.

Affected Version(s)

Wi-Fi Access Points Wi-Fi Access Points 22.0.0 <= 22.0.1F-32

Wi-Fi Access Points Wi-Fi Access Points 21.3.0 <= 21.3.0M-13

Wi-Fi Access Points Wi-Fi Access Points 1.0.0 < 21.3.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.