CVE-2026-33785 Details
Description
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a complete compromise of managed devices. Any user logged in, without requiring specific privileges, can issue 'request csds' CLI operational commands. These commands are only meant to be executed by high privileged or users designated for Juniper Device Manager (JDM) / Connected Security Distributed Services (CSDS) operations as they will impact all aspects of the devices managed via the respective MX. This issue affects Junos OS on MX Series: * 24.4 releases before 24.4R2-S3, * 25.2 releases before 25.2R2. This issue does not affect Junos OS releases before 24.4.
A missing authorization vulnerability has been identified in the CLI of Juniper Networks Junos OS on MX Series routers. This vulnerability allows local, authenticated users with low privileges to execute certain commands that can lead to a complete compromise of managed devices. Specifically, any logged-in user can issue 'request csds' CLI operational commands, which are intended for high-privileged users or those designated for Juniper Device Manager (JDM) / Connected Security Distributed Services (CSDS) operations. The affected commands can impact all aspects of devices managed through the respective MX. This vulnerability exists in Junos OS versions 24.4 releases prior to 24.4R2-S3 and 25.2 releases prior to 25.2R2. Junos OS versions before 24.4 are not affected.
Users can upgrade to Junos OS versions 24.4R2-S3, 25.2R2, 25.4R1, or any subsequent release. Additionally, access lists or firewall filters can be used to limit CLI access to trusted hosts and administrators, and CLI authorization can be implemented to prevent the execution of 'request csds' commands.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA107872 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 24.4 r2-s1 24.4 r2-s2 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 |
CPE
Remediation
| |
| juniper mx10004 | All versions |
CPE
Remediation
| |
| juniper mx10008 | All versions |
CPE
Remediation
| |
| juniper mx2008 | All versions |
CPE
Remediation
| |
| juniper mx2010 | All versions |
CPE
Remediation
| |
| juniper mx2020 | All versions |
CPE
Remediation
| |
| juniper mx204 | All versions |
CPE
Remediation
| |
| juniper mx240 | All versions |
CPE
Remediation
| |
| juniper mx301 | All versions |
CPE
Remediation
| |
| juniper mx304 | All versions |
CPE
Remediation
| |
| juniper mx480 | All versions |
CPE
Remediation
| |
| juniper mx960 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Apr 9, 2026 | New CVE Received | [email protected] |