Skip to content
COOEY

FAIL › dossier

Junos OS

PRODUCT

· dossier confidence 80%

Juniper's Junos OS has a concerning history of high-severity security vulnerabilities, particularly remote code execution flaws, indicating potential weaknesses in its security posture. These vulnerabilities frequently involve authentication bypasses and issues within the J-Web interface, requiring careful monitoring and patching.

PROFILE
CategoryNetworking Hardware/SoftwareWhat they doJunos OS is a network operating system developed by Juniper Networks, used on routers, switches, and security appliances. It provides a range of networking features and services for enterprise and service provider environments.
SECURITY POSTURE

Junos OS has demonstrated a history of significant security vulnerabilities, frequently involving remote code execution (RCE). The repeated occurrence of high-severity RCE vulnerabilities suggests potential weaknesses in the development and security review processes.

Notable failures
  • CVE-2023-36847: Missing authentication, arbitrary file upload
  • CVE-2023-36851: Missing authentication, file upload via J-Web
  • CVE-2023-36846: Missing authentication, file upload via J-Web
  • CVE-2023-36844: PHP External Variable Modification Vulnerability
  • CVE-2023-36845: PHP External Variable Modification Vulnerability
  • CVE-2025-21590: Arbitrary code injection due to improper isolation
Patterns: Repeated high-severity RCE vulnerabilities; Authentication bypass leading to file upload; Vulnerabilities in J-Web interface; PHP vulnerabilities
FAILURE HISTORY · 7
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2020-1631 high Juniper Junos OS path traversal flaw in J-Web and related services allows unauthenticated remote code execution.
2023-11-13 CVE-2023-36851 high Juniper Junos OS SRX Series missing authentication for critical function allows file upload via J-Web.
2023-11-13 CVE-2023-36846 high Juniper Junos OS SRX Series missing authentication for critical function allows file upload via J-Web.
2023-11-13 CVE-2023-36844 high Juniper Junos OS EX Series PHP External Variable Modification Vulnerability
2023-11-13 CVE-2023-36845 high Juniper Junos OS PHP External Variable Modification Vulnerability
2023-11-13 CVE-2023-36847 high Juniper Junos OS EX Series missing authentication for critical function allows arbitrary file upload.
2025-03-13 CVE-2025-21590 high Juniper Junos OS allowed local attackers with high privileges to inject arbitrary code due to improper isolation.
Open questions: What is the current status of remediation for the identified CVEs? · What are Juniper's internal processes for vulnerability management and patching? · What is the root cause of the recurring authentication bypass issues?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-03 03:49:41.174827+00:00