Executive brief
A vulnerability in Juniper Networks MX Series routers could allow unauthorized users to bypass web filtering protections. These devices are used to manage and secure network traffic, and this flaw allows specifically formatted web requests to reach restricted internal or external resources that should be blocked. This could lead to unauthorized access to sensitive downstream systems or data.
Technical details
A vulnerability classified as 'Use of Incorrectly-Resolved Name or Reference' (CWE-706) exists in the URL filtering plugin of Junos OS on MX Series devices. The flaw is triggered when the system processes a specifically formatted URL, causing the filtering mechanism to incorrectly resolve the reference and forward the request instead of blocking it. An unauthenticated, remote attacker can exploit this to bypass configured security policies and reach downstream network resources. The issue is resolved in several maintenance releases including 23.2R2-S7, 23.4R2-S8, 24.2R2-S5, 24.4R2-S4, 25.2R2-S1, and 25.4R1-S2.
Affected products
- Juniper Networks Junos OS All versions before 23.2R2-S7; 23.4 versions before 23.4R2-S8; 24.2 versions before 24.2R2-S5; 24.4 versions before 24.4R2-S4; 25.2 versions before 25.2R2-S1; 25.4 versions before 25.4R1-S2, 25.4R2
Timeline
- 2026-07-09: advisory: Initial advisory published by Juniper Networks