Executive brief
A vulnerability in Juniper Networks Junos OS allows unauthorized network users to bypass security filters on certain high-performance routers. This could allow an attacker to reach the device's management and control systems, potentially leading to unauthorized access or interference with network operations. The issue specifically affects MX Series routers using certain line cards when specific loopback interface configurations are used.
Technical details
An Improper Check for Unusual or Exceptional Conditions (CWE-754) exists in the Packet Forwarding Engine (PFE) of Junos OS on MX Series platforms. The vulnerability occurs when firewall filters are applied to a non-zero loopback interface (lo0.n) that resides in the global VRF/default routing instance. On affected hardware (MPC10, MPC11, LC4800, LC9600 line cards, and MX304), these filters fail to execute, allowing unauthenticated network traffic to bypass intended security restrictions and reach the control plane. Security engineers can verify the issue by checking if firewall counters for the affected filter remain at zero despite traffic. Patches are available in Junos OS versions 23.2R2-S6, 23.4R2-S7, 24.2R2, 24.4R2, and subsequent releases.
Affected products
- Juniper Networks Junos OS All versions before 23.2R2-S6, 23.4 versions before 23.4R2-S7, 24.2 versions before 24.2R2, 24.4 versions before 24.4R2
Timeline
- 2026-04-09: advisory: Initial publication of the advisory