CVE-2026-102168: Security Advisory 0194
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista Wi-Fi access pointsto a version that resolves this vulnerability.Fixed in 21.4.0M-12Patch Security Advisory 0194 - Upgrade
Upgrade
Arista Wi-Fi access pointsto a version that resolves this vulnerability.Fixed in 22.1.1F-61Patch Security Advisory 0194
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service issue?
Affected Arista Wi-Fi access points are exposed when Captive Portal is enabled on an SSID. An attacker must be able to connect as an unauthenticated wireless client to that Captive-Portal-enabled SSID.
What does an attacker need to do to trigger the issue?
The attacker sends a crafted HTTP request to the portal service after connecting to the affected wireless network. No authentication or user interaction is required.
What is the impact after successful exploitation?
The crafted request crashes the portal service, causing a temporary denial of service. The service automatically restarts, and remote code execution is not possible.