Denial of Service Vulnerability in Arista Wi-Fi Access Points with Captive Portal
CVE-2026-102169

7.1HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-102169?

An unauthenticated wireless client connected to a captive-portal-enabled SSID on select Arista Wi-Fi access points can exploit this vulnerability by sending a specially crafted HTTP request. This action can lead to the crashing of the captive portal service. While the service automatically restarts, it is susceptible to a sustained low-rate attack, which may result in a continuous denial of service, disrupting the portal function for all users. It is important to note that this vulnerability does not allow for remote code execution.

Affected Version(s)

Wi-Fi Access Points Wi-Fi Access Points 22.0.0 <= 22.0.1F-32

Wi-Fi Access Points Wi-Fi Access Points 21.3.0 <= 21.3.0M-13

Wi-Fi Access Points Wi-Fi Access Points 1.0.0 < 21.3.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.