CVE-2026-102169
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Oct 06, 2026
Vendor
unknown
Description
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the captive portal. Remote code execution is not possible.