OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-102168 (CVSS 7.1)

NVD · officialPublished Oct 6, 2026Risk 23/100

On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible.

CVSS
7.1
AV:AdjacentAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source