CVE-2026-102168: high-severity vulnerability in Arista Networks Wi-Fi Access Points
Security Advisory 0194
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
Arista Networks · Wi-Fi Access PointsRelated CVEs — Arista Networks Wi-Fi Access Points
In the same product, most dangerous first.
CVE-2026-102163HIGHSecurity Advisory 0195EPSS 0.3%CVE-2026-102169HIGHSecurity Advisory 0194EPSS 0.3%CVE-2026-102162CRITICALSecurity Advisory 0193EPSS 0.2%CVE-2026-102165HIGHSecurity Advisory 0198EPSS 0.2%CVE-2026-102167CRITICALSecurity Advisory 0197EPSS 0.2%CVE-2026-102164LOWSecurity Advisory 0196EPSS 0.2%