CVE-2026-102165
Received Received - Intake

Remote Code Execution in Arista Wi-Fi Access Points

Vulnerability report for CVE-2026-102165, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Arista Networks, Inc.

Description

On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Arista Networks Wi-Fi Access Points 22.0.0
Arista Networks Wi-Fi Access Points 21.3.0
Arista Networks Wi-Fi Access Points 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Arista Wi-Fi access points where an unauthenticated attacker with network access to the capture service can send a crafted packet. This may cause the service to crash or potentially allow remote code execution. The exploit requires a non-default streaming mode that is not commonly used.

Detection Guidance

Detecting this vulnerability requires monitoring for crashes in the capture service on Arista Wi-Fi access points. Check logs for service crashes or unusual network traffic patterns. Since the exploit requires a non-default streaming mode, verify if this mode is enabled on your devices.

Impact Analysis

An attacker could disrupt the capture service by crashing it or execute arbitrary code remotely. This could lead to service unavailability or unauthorized access to the affected system, depending on the attacker's goals and the system's configuration.

Mitigation Strategies

Disable the non-default streaming mode if enabled. Ensure the capture service is not exposed to untrusted networks. Apply any available patches or updates from Arista to address the vulnerability. Monitor network traffic for signs of exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102165. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart