CVE-2026-33774: Junos OS: MX Series: Firewall filters on lo0.<non-0> in the default routing instance are not in effect
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the configured firewall filter and access the control-plane of the device.
On MX platforms with
MPC10, MPC11, LC4800 or LC9600
line cards, and MX304, firewall filters applied on a loopback interface lo0.n (where n is a non-0 number) don't get executed when lo0.n is in the global VRF / default routing-instance.
An affected configuration would be:
user@host# show configuration interfaces lo0 | display set set interfaces lo0 unit 1 family inet filter input <filter-name>
where a firewall filter is applied to a non-0 loopback interface, but that loopback interface is not referred to in any routing-instance (RI) configuration, which implies that it's used in the default RI.
The issue can be observed with the CLI command:
user@device> show firewall counter filter <filtername>
not showing any matches.
This issue affects Junos OS on MX Series:
all versions before 23.2R2-S6, 23.4 versions before 23.4R2-S7, 24.2 versions before 24.2R2, 24.4 versions before 24.4R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS on MX Seriesto a version that resolves this vulnerability.Fixed in 23.2R2-S6 - Upgrade
Upgrade
Juniper Networks Junos OS on MX Seriesto a version that resolves this vulnerability.Fixed in 23.4R2-S7 - Upgrade
Upgrade
Juniper Networks Junos OS on MX Seriesto a version that resolves this vulnerability.Fixed in 24.2R2 - Upgrade
Upgrade
Juniper Networks Junos OS on MX Seriesto a version that resolves this vulnerability.Fixed in 24.4R2 - Upgrade
Upgrade
Juniper Networks Junos OS on MX Seriesto a version that resolves this vulnerability.Fixed in 25.2R1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33774?
CVE-2026-33774 has a severity rating of medium, specifically 6.9.
How do I fix CVE-2026-33774?
To resolve CVE-2026-33774, upgrade to one of the fixed software releases: 23.2R2-S6, 23.4R2-S7, 24.2R2, 24.4R2, 25.2R1, or any subsequent releases.
What type of attack does CVE-2026-33774 allow?
CVE-2026-33774 allows an unauthenticated, network-based attacker to bypass configured firewall filters on Juniper MX Series devices.
Which devices are affected by CVE-2026-33774?
CVE-2026-33774 affects Juniper Networks Junos OS on MX Series platforms.
What component of Junos OS is vulnerable in CVE-2026-33774?
CVE-2026-33774 involves a vulnerability in the packet forwarding engine (pfe) of Junos OS.