CVE-2026-102168
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Oct 06, 2026
Vendor
unknown
Description
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible.