Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-102169 has been fixed in the following releases: - 22.1.1F-61 and later release in the 22.x train - 21.4.0M-12 and later releases in the 21.x train
Vendor Workaround
If Captive Portal is not required, disabling Captive Portal on all SSIDs eliminates exposure. If a Captive Portal is required, there is no mitigation available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the captive portal. Remote code execution is not possible. | |
| Title | Security Advisory 0194 | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:07:05.528Z
Reserved: 2026-09-28T17:45:17.723Z
Link: CVE-2026-102169
Updated: 2026-10-06T20:07:00.828Z
Status : Received
Published: 2026-10-06T20:17:12.197
Modified: 2026-10-06T21:17:04.030
Link: CVE-2026-102169
No data.
OpenCVE Enrichment
No data.