CVE-2026-21913: Junos OS: EX4000: A high volume of traffic destined to the device leads to a crash and restart
An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
On EX4000 models with 48 ports (EX4000-48T, EX4000-48P, EX4000-48MP) a high volume of traffic destined to the device will cause an FXPC crash and restart, which leads to a complete service outage until the device has automatically restarted.
The following reboot reason can be seen in the output of 'show chassis routing-engine' and as a log message:
reason=0x4000002 reasonstring=0x4000002:watchdog + panic with core dump
This issue affects Junos OS on EX4000-48T, EX4000-48P and EX4000-48MP:
24.4 versions before 24.4R2, 25.2 versions before 25.2R1-S2, 25.2R2.
This issue does not affect versions before 24.4R1 as the first Junos OS version for the EX4000 models was 24.4R1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21913?
CVE-2026-21913 is classified as a critical vulnerability due to its potential to cause a Denial of Service.
How do I fix CVE-2026-21913?
To mitigate CVE-2026-21913, users should upgrade their Junos OS to a version higher than 25.2R2.
What devices are affected by CVE-2026-21913?
CVE-2026-21913 specifically affects the EX4000 models running vulnerable versions of Junos OS.
What type of attack does CVE-2026-21913 facilitate?
CVE-2026-21913 allows an unauthenticated network-based attacker to crash the device, leading to a restart.
Is authentication required for exploiting CVE-2026-21913?
No, CVE-2026-21913 can be exploited without authentication due to its incorrect initialization of resources.