Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the

advanced forwarding toolkit (evo-aftmand)

of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the

evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control.

Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC.

This issue affects Junos OS Evolved on PTX :


* from 24.4R2-EVO before 24.4R2-S3-EVO;
* from 25.2 before 25.2R2-EVO.
Published: 2026-07-09
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Juniper Networks Junos OS Evolved 24.4R2‑EVO and 25.2 series on PTX Series and affects the advanced forwarding toolkit (evo‑aftmand). The flaw allows an attacker to continuously send ECMP routing updates that create unilist ECMP routes; the router processes these updates incorrectly, corrupting internal state and causing the evo‑aftmand process to crash, which results in a denial‑of‑service that requires a reboot or FPC restart to recover. The failure is triggered by a sequence of events that are largely outside the attacker’s direct control, meaning the attacker may need to rely on normal routing protocol exchanges or injection of malformed updates to trigger the unilist behavior.

Affected Systems

The affected vendor is Juniper Networks and the product is Junos OS Evolved PTX Series. Vulnerable releases include any 24.4R2‑EVO version earlier than 24.4R2‑S3‑EVO and any 25.2 version earlier than 25.2R2‑EVO.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score, being less than 1%, suggests a very low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network‑based and requires an unauthenticated attacker to continuously inject ECMP routing updates that create unilist ECMP routes. Successful exploitation also depends on specific routing protocol events that are not entirely controllable by the attacker, which may limit the practicality of the attack.

Generated by OpenCVE AI on July 31, 2026 at 13:20 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 24.4R2-S3-EVO, 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade all Junos OS Evolved PTX Series devices to 24.4R2‑S3‑EVO, 25.2R2‑EVO, 25.4R1‑EVO, or any later release that includes the fix.
  • After upgrading, reboot the FPC or the entire device to clear any corrupted state and reinitialize the PFE.
  • Monitor routing tables and PFE logs for abrupt unilist ECMP changes and enable detailed logging of routing update events to detect anomalous activity.

Generated by OpenCVE AI on July 31, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os Evolved
Vendors & Products Juniper Networks
Juniper Networks junos Os Evolved

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control. Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC. This issue affects Junos OS Evolved on PTX : * from 24.4R2-EVO before 24.4R2-S3-EVO; * from 25.2 before 25.2R2-EVO.
Title Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates results in PFE crash
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:U/V:C/RE:M/U:Green'}


Subscriptions

Juniper Junos Os Evolved Ptx1000-72q Ptx10000 Ptx10001 Ptx10001-36mr Ptx100016 Ptx10002 Ptx10002-36qdd Ptx10002-60c Ptx10003 Ptx10003 160c Ptx10003 80c Ptx10003 81cd Ptx10004 Ptx10008 Ptx10016 Ptx12008 Ptx3000 Ptx5000
Juniper Networks Junos Os Evolved
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:22:17.928Z

Reserved: 2026-03-23T19:46:13.673Z

Link: CVE-2026-33794

cve-icon Vulnrichment

Updated: 2026-07-10T14:22:14.539Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-09T21:16:54.790

Modified: 2026-07-13T12:57:12.750

Link: CVE-2026-33794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:30:17Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions