Denial of Service Vulnerability in Arista Wi-Fi Access Points with Captive Portal Feature
CVE-2026-102168

7.1HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-102168?

On affected Arista Wi-Fi access points equipped with the Captive Portal feature, an unauthorized wireless client can exploit the system by sending a specifically crafted HTTP request. This action causes the portal service to crash, leading to a temporary outage until the service automatically restarts. Notably, this vulnerability does not allow for remote code execution, but it significantly disrupts service availability on the network.

Affected Version(s)

Wi-Fi Access Points Wi-Fi Access Points 22.0.0 <= 22.0.1F-32

Wi-Fi Access Points Wi-Fi Access Points 21.3.0 <= 21.3.0M-13

Wi-Fi Access Points Wi-Fi Access Points 1.0.0 < 21.3.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.