Metrics
Affected Vendors & Products
No advisories yet.
Solution
CVE-2026-102162 has been fixed in the following releases: - 22.1.1F-61 and later release in the 22.x train - 21.4.0M-12 and later releases in the 21.x train
Workaround
If captive portal and application firewall are not required, disabling these features on all SSIDs eliminates exposure to this vulnerability.
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts. | |
| Title | Security Advisory 0193 | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:06:08.243Z
Reserved: 2026-09-28T17:41:09.358Z
Link: CVE-2026-102162
Updated: 2026-10-06T20:06:00.911Z
Status : Received
Published: 2026-10-06T20:17:11.377
Modified: 2026-10-06T21:17:03.117
Link: CVE-2026-102162
No data.
OpenCVE Enrichment
No data.