Denial of Service Vulnerability in Arista Wi-Fi Access Points with Captive Portal Feature
CVE-2026-102168
7.1HIGH
What is CVE-2026-102168?
On affected Arista Wi-Fi access points equipped with the Captive Portal feature, an unauthorized wireless client can exploit the system by sending a specifically crafted HTTP request. This action causes the portal service to crash, leading to a temporary outage until the service automatically restarts. Notably, this vulnerability does not allow for remote code execution, but it significantly disrupts service availability on the network.
Affected Version(s)
Wi-Fi Access Points Wi-Fi Access Points 22.0.0 <= 22.0.1F-32
Wi-Fi Access Points Wi-Fi Access Points 21.3.0 <= 21.3.0M-13
Wi-Fi Access Points Wi-Fi Access Points 1.0.0 < 21.3.0
