Junglewise Threat Intelligence

CVE-2026-33801: Juniper Networks Junos OS DoS in routing protocol daemon

CVE-2026-33801 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Technologies: Juniper Networks Junos OS Evolved. Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks' routing software can allow a nearby attacker to crash the device's routing services. This software is used to manage network traffic on enterprise-grade routers and switches. An exploit would cause a complete service outage, disrupting network connectivity until the system automatically restarts and restores its routing tables.

Technical details

An Improper Check for Unusual or Exceptional Conditions (CWE-754) exists in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved. An adjacent, unauthenticated attacker can trigger this vulnerability by sending a specifically malformed non-inet/inet6 unicast BGP update over an established BGP session. This causes the RPD to crash and restart, leading to a complete service outage until routing reconverges. The crash occurs before the update is readvertised, preventing downstream propagation of the malformed packet. The issue is fixed in Junos OS 25.2R2 and Junos OS Evolved 25.2R2-EVO.

Affected products

  • Juniper Networks Junos OS 25.2 before 25.2R2
  • Juniper Networks Junos OS Evolved 25.2 before 25.2R2-EVO

Timeline

  • 2026-07-09: advisory: Initial publication of JSA110076 / CVE-2026-33801

References

Related threats