Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters.

On MX Series devices with MPC10/11, LC4800/9600, and MX304 with subscribers configured on static interfaces, ingress firewall filters are not enforced, so that neither protocol level nor upstream bandwidth limitation are in effect. 


This issue affects Junos OS on MX with MPC10/11, LC4800/9600/4802, and MX304:


* 23.2 versions from 23.2R2-S1 before 23.2R2-S7,
* 23.4 versions from 23.4R2 before 23.4R2-S7,
* 24.2 versions before 24.2R2-S3,
* 24.4 versions before 24.4R2-S2,
* 25.2 versions before 25.2R2.
Published: 2026-07-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Check for Unusual or Exceptional Conditions flaw (CWE‑754) in Juniper Networks Junos OS on MX Series routers allows adjacent subscribers that are defined on static interfaces to bypass all ingress firewall filters and bandwidth limits. Because the packet forwarding engine does not enforce the configured filters for static subscriber interfaces, attacker‑controlled traffic can enter or leave the router without inspection or rate control, exposing critical internal traffic to potential integrity and confidentiality compromise.

Affected Systems

The affected products are Juniper Networks Junos OS running on MX Series routers, including the MPC10, MPC11, LC4800, LC9600, LC4802, and MX304 models. Vulnerable firmware versions are: 23.2R2‑S1 through 23.2R2‑S6, all 23.4R2 builds prior to 23.4R2‑S7, all 24.2 releases before 24.2R2‑S3, all 24.4 releases before 24.4R2‑S2, and all 25.2 releases older than 25.2R2.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, while an EPSS score of less than 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers would need physical or near‑physical proximity to a subscriber interface configured with a static address on the same MX device; remote exploitation through the public Internet is not supported. Once bypassed, the flaw allows malicious or unmonitored traffic to flow through the router, potentially compromising the confidentiality or integrity of downstream traffic.

Generated by OpenCVE AI on August 3, 2026 at 04:19 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S7, 24.2R2-S3, 24.4R2-S2, 25.2R2, 25.4R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Junos OS to a patched release (23.2R2‑S7 or newer, 23.4R2‑S7 or newer, 24.2R2‑S3 or newer, 24.4R2‑S2 or newer, or 25.2R2 or newer).
  • Reconfigure all static subscriber interfaces to use dynamic addressing or move them to a separate VLAN that is not affected by this issue until the operating system is patched.
  • Apply interface‑level access lists that block undesired traffic and enforce rate limiting directly on the subscriber interface before the packet forwarding engine processes the packets.

Generated by OpenCVE AI on August 3, 2026 at 04:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On MX Series devices with MPC10/11, LC4800/9600, and MX304 with subscribers configured on static interfaces, ingress firewall filters are not enforced, so that neither protocol level nor upstream bandwidth limitation are in effect.  This issue affects Junos OS on MX with MPC10/11, LC4800/9600/4802, and MX304: * 23.2 versions from 23.2R2-S1 before 23.2R2-S7, * 23.4 versions from 23.4R2 before 23.4R2-S7, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R2.
Title Junos OS: MX Series: For subscribers configured on static interfaces, input filters are not in effect
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/AU:Y/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:37:16.783Z

Reserved: 2026-06-23T16:27:00.249Z

Link: CVE-2026-57031

cve-icon Vulnrichment

Updated: 2026-07-10T14:36:34.009Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-09T22:17:08.827

Modified: 2026-07-10T17:49:57.737

Link: CVE-2026-57031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:30:18Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions