CVE-2026-102167: Security Advisory 0197
On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista Wi-Fi access pointsto a version that resolves this vulnerability.Fixed in 21.4.0M-12 - Upgrade
Upgrade
Arista Wi-Fi access pointsto a version that resolves this vulnerability.Fixed in 22.1.1F-61
Event History
Frequently Asked Questions
Which deployments are exposed to attack?
Affected Arista Wi-Fi access points are exposed only to attackers on the same network segment as the access point’s wired uplink. The attacker does not need authentication or user interaction.
What could successful exploitation do?
An attacker may be able to crash the sensor service, causing a denial of service. The advisory also indicates that remote code execution may be possible.
What network condition is required for exploitation?
The attacker must be able to reach the wired uplink network endpoints from the same network segment. This limits exposure relative to attacks originating from unrelated network segments.