---
id: CVE-2026-102167
title: >-
  On affected Arista Wi-Fi access points, a memory corruption vulnerability
  exists in access point's wired uplink network endpoints
summary: >-
  On affected Arista Wi-Fi access points, a memory corruption vulnerability
  exists in access point's wired uplink network endpoints. An unauthenticated
  attacker can crash the sensor service or potentially achieve remote code
  execution. Exp…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-121
vendor: Arista Networks
product: Wi-Fi Access Points
affected:
  - wi-fi_access_points >= 22.0.0 <= 22.0.1F-32
  - wi-fi_access_points >= 21.3.0 <= 21.3.0M-13
  - wi-fi_access_points >= 1.0.0 < 21.3.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:03.633'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102167'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24813-security-advisory-0197
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-06T20:00:24.458435Z'
ingestedAt: '2026-10-06T20:16:42.483Z'
---

## Overview

On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
