Denial of Service Vulnerability in Arista Wi-Fi Access Points with Captive Portal
CVE-2026-102169
7.1HIGH
What is CVE-2026-102169?
An unauthenticated wireless client connected to a captive-portal-enabled SSID on select Arista Wi-Fi access points can exploit this vulnerability by sending a specially crafted HTTP request. This action can lead to the crashing of the captive portal service. While the service automatically restarts, it is susceptible to a sustained low-rate attack, which may result in a continuous denial of service, disrupting the portal function for all users. It is important to note that this vulnerability does not allow for remote code execution.
Affected Version(s)
Wi-Fi Access Points Wi-Fi Access Points 22.0.0 <= 22.0.1F-32
Wi-Fi Access Points Wi-Fi Access Points 21.3.0 <= 21.3.0M-13
Wi-Fi Access Points Wi-Fi Access Points 1.0.0 < 21.3.0
