CVE-2026-102169: Security Advisory 0194
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the captive portal. Remote code execution is not possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista Wi-Fi access pointsto a version that resolves this vulnerability.Fixed in 21.4.0M-12 - Upgrade
Upgrade
Arista Wi-Fi access pointsto a version that resolves this vulnerability.Fixed in 22.1.1F-61
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service issue?
Affected Arista Wi-Fi access points are exposed when Captive Portal is enabled on an SSID. An attacker must be an unauthenticated wireless client connected to that captive-portal-enabled SSID.
What does an attacker need to do, and what is the impact?
The attacker sends a crafted HTTP request to crash the portal service. Although the service automatically restarts, a sustained low-rate attack can keep the captive portal unavailable; remote code execution is not possible.