CVE-2026-33774 Details
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the configured firewall filter and access the control-plane of the device. On MX platforms with MPC10, MPC11, LC4800 or LC9600 line cards, and MX304, firewall filters applied on a loopback interface lo0.n (where n is a non-0 number) don't get executed when lo0.n is in the global VRF / default routing-instance. An affected configuration would be: user@host# show configuration interfaces lo0 | display set set interfaces lo0 unit 1 family inet filter input <filter-name> where a firewall filter is applied to a non-0 loopback interface, but that loopback interface is not referred to in any routing-instance (RI) configuration, which implies that it's used in the default RI. The issue can be observed with the CLI command: user@device> show firewall counter filter <filter_name> not showing any matches. This issue affects Junos OS on MX Series: * all versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R2.
A vulnerability in the packet forwarding engine of Juniper Networks Junos OS on MX Series devices allows an unauthenticated, network-based attacker to bypass configured firewall filters and access the device's control plane. This issue occurs on MX platforms with MPC10, MPC11, LC4800, LC9600 line cards, and MX304, affecting all versions prior to 23.2R2-S6, 23.4 versions prior to 23.4R2-S7, 24.2 versions prior to 24.2R2, and 24.4 versions prior to 24.4R2. The vulnerability arises because firewall filters applied to non-zero loopback interfaces in the global VRF or default routing instance are not executed. As a result, filters may not be applied as intended, leaving the control plane accessible without proper protection.
Users can rename the affected loopback logical unit from a non-zero value to zero, which will resolve the issue. The vulnerability has also been fixed in the Junos OS releases 23.2R2-S6, 23.4R2-S7, 24.2R2, 24.4R2, 25.2R1, and all subsequent releases.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA107865 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 23.2 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.2 r2-s5 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 23.4 r2-s6 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.4 r1 24.4 r1-s2 24.4 r1-s3 |
CPE
Remediation
| |
| juniper lc4800 | All versions |
CPE
Remediation
| |
| juniper mpc10 | All versions |
CPE
Remediation
| |
| juniper mpc11 | All versions |
CPE
Remediation
| |
| juniper mx304 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 9, 2026 | New CVE Received | [email protected] |