Executive brief
Juniper Networks CTP OS, an operating system for Circuit to Packet platforms, contains a flaw where password complexity settings are not properly saved or enforced. This allows users to set weak passwords that do not meet corporate security standards. An attacker could exploit this by guessing weak credentials to gain unauthorized access and potentially take full control of the networking device.
Technical details
A vulnerability in the password management function of Juniper Networks CTP OS (versions 9.2R1 and 9.2R2) prevents administrator-defined password complexity requirements from being saved. Although the management menu allows these settings to be configured, the system fails to enforce them, as confirmed by the 'Show password requirements' option. This root cause (CWE-521) allows for the creation of weak local account passwords. A network-based attacker can leverage this to perform credential-guessing attacks. Successful exploitation could lead to unauthorized access and full administrative control over the affected device.
Affected products
- Juniper Networks CTP OS 9.2R1, 9.2R2
Timeline
- 2026-04-09: disclosed
- 2026-04-09: advisory