CVE-2026-57032: Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path causes fxpc process crash

Published Jul 9, 2026
·
Updated

An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS).

If an attempt is made to subscribe to an unsupported telemetry sensor path on EX2300, EX3400, EX4000, EX4100 and EX4400 via gRPC, this causes the FPC to crash. This leads to a complete service outage until the module has automatically restarted.

The following log message can be seen when this issue happens:

agentd[<PID>]: AGENTDRESOURCENOTFOUND: No resource name found for <sensor>

This issue affects Junos OS on

EX2300, EX3400, EX4000, EX4100 and EX4400

devices:

all versions before 23.2R2-S7, 23.4 versions before 23.4R2-S8, 24.2 versions before 24.2R2-S5, 24.4 versions before 24.4R2.

Affected Software

47 affected components
Juniper Networks Junos OS on EX Series<23.2R2-S7, >23.4<23.4R2-S8, >24.2<24.2R2-S5, >24.4<24.4R2
All of the following
Any of the following
Juniper Junos<23.2
Juniper Junos=23.2
Juniper Junos=23.2-r1
Juniper Junos=23.2-r1-s1
Juniper Junos=23.2-r1-s2
Juniper Junos=23.2-r2
Juniper Junos=23.2-r2-s1
Juniper Junos=23.2-r2-s2
Juniper Junos=23.2-r2-s3
Juniper Junos=23.2-r2-s4
Juniper Junos=23.2-r2-s5
Juniper Junos=23.2-r2-s6
Juniper Junos=23.4
Juniper Junos=23.4-r1
Juniper Junos=23.4-r1-s1
Juniper Junos=23.4-r1-s2
Juniper Junos=23.4-r2
Juniper Junos=23.4-r2-s1
Juniper Junos=23.4-r2-s2
Juniper Junos=23.4-r2-s3
Juniper Junos=23.4-r2-s4
Juniper Junos=23.4-r2-s5
Juniper Junos=23.4-r2-s6
Juniper Junos=23.4-r2-s7
Juniper Junos=24.2
Juniper Junos=24.2-r1
Juniper Junos=24.2-r1-s1
Juniper Junos=24.2-r1-s2
Juniper Junos=24.2-r2
Juniper Junos=24.2-r2-s1
Juniper Junos=24.2-r2-s2
Juniper Junos=24.2-r2-s3
Juniper Junos=24.2-r2-s4
Juniper Junos=24.4
Juniper Junos=24.4-r1
Juniper Junos=24.4-r1-s2
Juniper Junos=24.4-r1-s3
Any of the following
Juniper EX2300
Juniper EX2300-C
Juniper EX3400
Juniper EX4000
Juniper EX4100
Juniper Ex4100-f
Juniper Ex4100-h
Juniper Ex4100-h-12t
Juniper EX4400

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400) to a version that resolves this vulnerability.

    Fixed in 23.2R2-S7
  2. Upgrade

    Upgrade Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400) to a version that resolves this vulnerability.

    Fixed in 23.4R2-S8
  3. Upgrade

    Upgrade Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400) to a version that resolves this vulnerability.

    Fixed in 24.2R2-S5
  4. Upgrade

    Upgrade Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400) to a version that resolves this vulnerability.

    Fixed in 24.4R2
  5. Upgrade

    Upgrade Juniper Networks Junos OS (EX Series pfe/telemetry on EX2300, EX3400, EX4000, EX4100, EX4400) to a version that resolves this vulnerability.

    Fixed in 25.2R1
  6. Compensating control

    Avoid subscribing via gRPC to unsupported telemetry sensor paths on EX2300, EX3400, EX4000, EX4100, and EX4400 (this can trigger an FPC crash and complete service outage until the module restarts).

  7. Operational

    If the issue is triggered and the fxpc/agentd-related modules crash and restart, verify service availability and monitor for AGENTD_RESOURCE_NOT_FOUND log entries indicating unsupported telemetry sensor path subscription attempts (e.g., agentd[<PID>]: AGENTD_RESOURCE_NOT_FOUND: No resource name found for <sensor>).

Event History

Jul 9, 2026
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-57032?

The severity of CVE-2026-57032 is medium with a score of 6.5.

2

How do I fix CVE-2026-57032?

To fix CVE-2026-57032, ensure that you are not subscribing to unsupported telemetry sensor paths on Junos OS EX Series devices.

3

What impact does CVE-2026-57032 have on my system?

CVE-2026-57032 allows an authenticated attacker to cause a Denial-of-Service (DoS) by leading to a crash of the fxpc process.

4

Who is affected by CVE-2026-57032?

CVE-2026-57032 affects devices running Juniper Networks Junos OS on EX Series that allow subscription to telemetry sensors.

5

What conditions are required to exploit CVE-2026-57032?

An attacker must have authenticated low privileges and attempt to subscribe to an unsupported telemetry sensor path to exploit CVE-2026-57032.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203