Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters.

On MX Series devices with MPC10/11, LC4800/9600, and MX304 with subscribers configured on static interfaces, ingress firewall filters are not enforced, so that neither protocol level nor upstream bandwidth limitation are in effect. 


This issue affects Junos OS on MX with MPC10/11, LC4800/9600/4802, and MX304:


* 23.2 versions from 23.2R2-S1 before 23.2R2-S7,
* 23.4 versions from 23.4R2 before 23.4R2-S7,
* 24.2 versions before 24.2R2-S3,
* 24.4 versions before 24.4R2-S2,
* 25.2 versions before 25.2R2.
Published: 2026-07-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Check for Unusual or Exceptional Conditions flaw in the packet forwarding engine of Juniper Networks Junos OS on MX Series routers enables adjacent subscribers who connect through static interfaces to bypass all configured ingress firewall filters and bandwidth limitations. Because this flaw allows traffic from those subscribers to pass the router unchecked, the primary impact is that unfiltered or potentially malicious packets can reach the internal network, exposing it to security threats. This vulnerability is identified as CWE‑754.

Affected Systems

The affected systems are Juniper Networks Junos OS running on MX Series routers, specifically MPC10, MPC11, LC4800, LC9600, and MX304 models. Affected releases include all 23.2R2‑S1 through 23.2R2‑S6, all 23.4R2 releases before 23.4R2‑S7, all 24.2 releases prior to 24.2R2‑S3, all 24.4 releases before 24.4R2‑S2, and all 25.2 releases older than 25.2R2. Versions released after these thresholds are not affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity vulnerability, and the EPSS score of less than 1 % suggests exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need direct local access to an adjacent subscriber interface configured with a static address on the same MX device; the attack path does not permit remote exploitation. Thus, the attack surface is limited, but the vulnerability permits unfiltered traffic into the network, representing a tangible risk to confidentiality and integrity of network traffic.

Generated by OpenCVE AI on July 26, 2026 at 14:38 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S7, 24.2R2-S3, 24.4R2-S2, 25.2R2, 25.4R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Junos OS to a patched release: 23.2R2‑S7 or later, 23.4R2‑S7 or later, 24.2R2‑S3 or later, 24.4R2‑S2 or later, or 25.2R2 or later.
  • If upgrading is not immediately feasible, avoid using static interfaces for new subscriber configurations or route critical traffic through dynamic interfaces until the issue is fixed.
  • Validate that ingress firewall filters and bandwidth limits are enforced by testing traffic from an adjacent subscriber.
  • No known workaround is available for this issue.

Generated by OpenCVE AI on July 26, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On MX Series devices with MPC10/11, LC4800/9600, and MX304 with subscribers configured on static interfaces, ingress firewall filters are not enforced, so that neither protocol level nor upstream bandwidth limitation are in effect.  This issue affects Junos OS on MX with MPC10/11, LC4800/9600/4802, and MX304: * 23.2 versions from 23.2R2-S1 before 23.2R2-S7, * 23.4 versions from 23.4R2 before 23.4R2-S7, * 24.2 versions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R2.
Title Junos OS: MX Series: For subscribers configured on static interfaces, input filters are not in effect
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/AU:Y/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:37:16.783Z

Reserved: 2026-06-23T16:27:00.249Z

Link: CVE-2026-57031

cve-icon Vulnrichment

Updated: 2026-07-10T14:36:34.009Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T14:45:06Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions