CVE-2026-102167

Received
Published: 06 Oct 2026, 19:40
Last modified:06 Oct 2026, 20:00

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9 CRITICAL
v4.0 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Oct 2026, 19:40
Published
Vulnerability first disclosed
06 Oct 2026, 20:00
Last Modified
Vulnerability information updated

Description

On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.

CVSS Metrics

  • v4.0•CRITICAL•Score: 9CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
  • v4.0•CRITICAL•Score: 9CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1•HIGH•Score: 7.5CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Techniques & Countermeasures

  • CWE-121•Stack-based Buffer Overflow

    A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Affected Systems

  • arista networks•wi-fi access points

    ≥ 22.0.0, ≤ 22.0.1F-32 | ≥ 21.3.0, ≤ 21.3.0M-13 | ≥ 1.0.0, < 21.3.0

References (1)