Project Subscriptions
No data.
No advisories yet.
Solution
CVE-2026-102168 has been fixed in the following releases: - 22.1.1F-61 and later release in the 22.x train - 21.4.0M-12 and later releases in the 21.x train
Workaround
If Captive Portal is not required, disabling Captive Portal on all SSIDs eliminates exposure. If a Captive Portal is required, there is no mitigation available.
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible. | |
| Title | Security Advisory 0194 | |
| Weaknesses | CWE-191 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:06:39.424Z
Reserved: 2026-09-28T17:45:17.723Z
Link: CVE-2026-102168
No data.
Status : Received
Published: 2026-10-06T20:17:12.067
Modified: 2026-10-06T20:17:12.067
Link: CVE-2026-102168
No data.
OpenCVE Enrichment
No data.