{"id":"CVE-2026-102167","title":"On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints","summary":"On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exp…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-121"],"vendor":"Arista Networks","product":"Wi-Fi Access Points","affected":["wi-fi_access_points >= 22.0.0 <= 22.0.1F-32","wi-fi_access_points >= 21.3.0 <= 21.3.0M-13","wi-fi_access_points >= 1.0.0 < 21.3.0"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T21:17:03.633","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102167","references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24813-security-advisory-0197","label":"psirt@arista.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-06T20:00:24.458435Z"},"ingestedAt":"2026-10-06T20:16:42.483Z","slug":"CVE-2026-102167","body":"## Overview\n\nOn affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}