Junglewise Threat Intelligence

CVE-2026-57031: Juniper Networks Junos OS firewall filter bypass in MX Series PFE

CVE-2026-57031 · Severity: medium · CVSS 4.7 · Published 2026-07-09

Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks MX Series routers could allow network subscribers to bypass security filters. This means that safety measures intended to restrict certain types of traffic or limit how much bandwidth a user can consume may not be enforced. This could lead to unauthorized network activity or excessive resource usage by individual subscribers.

Technical details

An Improper Check for Unusual or Exceptional Conditions (CWE-754) exists in the Packet Forwarding Engine (PFE) of Junos OS. On MX Series devices equipped with MPC10/11, LC4800/9600, or MX304 line cards where subscribers are configured on static interfaces, ingress firewall filters are not enforced. This failure allows adjacent subscribers to bypass protocol-level restrictions and upstream bandwidth limitations. The vulnerability is reachable via the adjacent network and requires no authentication. Fixed versions have been released across several Junos OS release trains including 23.2, 23.4, 24.2, 24.4, and 25.2.

Affected products

  • Juniper Networks Junos OS 23.2 versions from 23.2R2-S1 before 23.2R2-S7; 23.4 versions from 23.4R2 before 23.4R2-S7; 24.2 versions before 24.2R2-S3; 24.4 versions before 24.4R2-S2; 25.2 versions before 25.2R2

Timeline

  • 2026-07-09: advisory: Initial publication of JSA110091

References