Junglewise Threat Intelligence

CVE-2026-33771: Juniper Networks CTP OS weak password requirements in password management

CVE-2026-33771 · Severity: high · CVSS 7.4 · Published 2026-04-09

Vendors: Juniper Networks.

Executive brief

Juniper Networks CTP OS, an operating system for Circuit to Packet platforms, contains a flaw where password complexity settings are not properly saved or enforced. This allows users to set weak passwords that do not meet corporate security standards. An attacker could exploit this by guessing weak credentials to gain unauthorized access and potentially take full control of the networking device.

Technical details

A vulnerability in the password management function of Juniper Networks CTP OS (versions 9.2R1 and 9.2R2) prevents administrator-defined password complexity requirements from being saved. Although the management menu allows these settings to be configured, the system fails to enforce them, as confirmed by the 'Show password requirements' option. This root cause (CWE-521) allows for the creation of weak local account passwords. A network-based attacker can leverage this to perform credential-guessing attacks. Successful exploitation could lead to unauthorized access and full administrative control over the affected device.

Affected products

  • Juniper Networks CTP OS 9.2R1, 9.2R2

Timeline

  • 2026-04-09: disclosed
  • 2026-04-09: advisory

References