CVE-2026-33771Disclosure(juniper / ctp_operating_system)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch juniper ctp_operating_system systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can be verified with the menu option "Show password requirements". Failure to enforce the intended requirements can lead to weak passwords being used, which significantly increases the likelihood that an attacker can guess these and subsequently attain unauthorized access. This issue affects CTP OS versions 9.2R1 and 9.2R2.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-521

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ctp_operating_system

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ctp_operating_system

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 104-0904-10
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-091
Disclosure1
2026-04-101
Patch1
Full discourse2 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Two Critical vulnerabilities in #Juniper CTP OS & JSI. CVE-2026-33771 & CVE-2026-33784 CVSS: 9.1-9.3. Administrator set password requirements are not enforced on users and changing the default superuser password is not enforced on installation. #Patch #Patch #Patch

    Post summary

    The tweet warns of two critical Juniper CTP OS/JSI vulnerabilities (CVE‑2026‑33771/33784), details their CVSS scores and password enforcement flaws, and urges applying a patch.

    01002360
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33771 A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to ex… https://www.cve.org/CVERecord?id=CVE-2026-33771

    Post summary

    The note announces a new Juniper Networks CVE (Weak Password Requirements in CTP OS) that could be exploited by unauthenticated network attackers, but provides no PoC, exploit, or mitigation details.

    00000145
    57.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSjuniperctp_operating_system9.2--
OSjuniperctp_operating_system9.2--

Explore more