Junglewise Threat Intelligence

CVE-2026-33802: Juniper Networks Junos OS missing authorization in CLI on EX Series

CVE-2026-33802 · Severity: medium · CVSS 5.5 · Published 2026-07-09

Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks Junos OS allows a logged-in user with no special privileges to crash certain EX Series network switches. By running a specific command, an attacker can disrupt all network traffic passing through the switch. The system will eventually recover automatically, but the exploit causes a temporary total service outage.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Command Line Interface (CLI) of Juniper Networks Junos OS on specific EX Series switches (EX2300, EX4000, EX4100, EX4300-MP, and EX4400). An authenticated local attacker with low privileges can execute a specific 'request' command that should be restricted to privileged users. Successful exploitation results in a complete traffic impact (Denial-of-Service) until the system automatically recovers. The issue is resolved in several maintenance releases including 23.2R2-S6, 23.4R2-S8, 24.2R2-S4, 24.4R2-S3, 25.2R2, and 25.4R1-S1.

Affected products

  • Juniper Networks Junos OS 23.2R2 versions before 23.2R2-S6, 23.4 versions before 23.4R2-S8, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S3, 25.2 versions before 25.2R2, 25.4 versions before 25.4R1-S1

Timeline

  • 2026-07-09: advisory: Initial advisory publication

References