Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).

Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.


This issue affects:



* Junos OS versions 25.2 before 25.2R2;


* Junos OS Evolved versions 25.2 before 25.2R2-EVO.




This issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.
Published: 2026-07-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to inject a specially malformed BGP update into an existing BGP session, causing the routing protocol daemon (RPD) to crash and restart. The crash occurs before the update is readvertised, so it does not spread downstream, but it brings the router offline until routing reconvergence, resulting in a network service outage.

Affected Systems

Vulnerable routers are those running Junos OS or Junos OS Evolved versions prior to 25.2R2 (Junos OS) or 25.2R2‑EVO (Junos OS Evolved). This includes all 25.2 releases, but not the earlier 25.2R1 or earlier releases. The flaw can affect any router that participates in BGP sessions with adjacent peers, regardless of the operating network tier.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate‑to‑high severity, whereas the EPSS score of less than 1% reflects a very low exploitation probability in the current data set. The vulnerability is not listed in CISA’s KEV catalog, but because it leads to a router crash and outage, it remains a high‑priority concern for operators who require continuous BGP availability. The attack vector is likely adjacent, requiring an established BGP session with the target router. No workaround is available, so remediation must be performed through a software update.

Generated by OpenCVE AI on July 29, 2026 at 11:55 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 25.2R2, 25.4R1, and all subsequent releases. Junos OS Evolved: 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade the affected router to Junos OS 25.2R2 or later, or Junos OS Evolved 25.2R2‑EVO or later as released by Juniper
  • Enable BGP session authentication (e.g., MD5) or otherwise restrict BGP neighbors to trusted routers
  • Configure local route filtering to reject unicast non‑inet/inet6 updates that are not needed for your routing policy

Generated by OpenCVE AI on July 29, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Juniper Networks junos Os Evolved
Vendors & Products Juniper Networks
Juniper Networks junos Os
Juniper Networks junos Os Evolved

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS). Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation. This issue affects: * Junos OS versions 25.2 before 25.2R2; * Junos OS Evolved versions 25.2 before 25.2R2-EVO. This issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.
Title Junos OS and Junos OS Evolved: When a specifically malformed BGP route update is received RPD crashes
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os Junos Os Evolved
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T13:31:03.248Z

Reserved: 2026-03-23T19:46:13.673Z

Link: CVE-2026-33801

cve-icon Vulnrichment

Updated: 2026-07-10T13:30:58.746Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions