CVE-2026-21912
Last modified
CVE-2026-21912 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged attacker executing the 'show system firmware' CLI command to cause an LC480 or LC2101 line card to reset. On MX10k Series systems with LC480 or LC2101 line cards, repeated execution of the 'show system firmware' CLI command can cause the line card to crash and restart. Additionally, some time after the line card crashes, chassisd may also crash and restart, generating a core dump.This issue affects Junos OS on MX10k Series: * all versions before 21.2R3-S10, * from 21.4 before 21.4R3-S9, * from 22.2 before 22.2R3-S7, * from 22.4 before 22.4R3-S6, * from 23.2 before 23.2R2-S2, * from 23.4 before 23.4R2-S3, * from 24.2 before 24.2R2.. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged attacker executing the 'show system firmware' CLI command to cause an LC480 or LC2101 line card to reset. On MX10k Series systems with LC480 or LC2101 line cards, repeated execution of the 'show system firmware' CLI command can cause the line card to crash and restart. Additionally, some time after the line card crashes, chassisd may also crash and restart, generating a core dump.This issue affects Junos OS on MX10k Series: * all versions before 21.2R3-S10, * from 21.4 before 21.4R3-S9, * from 22.2 before 22.2R3-S7, * from 22.4 before 22.4R3-S6, * from 23.2 before 23.2R2-S2, * from 23.4 before 23.4R2-S3, * from 24.2 before 24.2R2.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:Amber
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | < 21.2 |
| Juniper | Junos | 21.2 |
| Juniper | Junos | 21.4 |
| Juniper | Junos | 22.2 |
| Juniper | Junos | 22.4 |
| Juniper | Junos | 23.2 |
| Juniper | Junos | 23.4 |
| Juniper | Junos | 24.2 |
References
- https://kb.juniper.net/JSA106011Vendor Advisory
- https://supportportal.juniper.net/JSA106011Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-21912?
How severe is CVE-2026-21912?
How do I fix CVE-2026-21912?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-21907A Use of a Broken or Risky Cryptographic Algorithm vulnerabi…8.2
- CVE-2026-21908A Use After Free vulnerability was identified in the 802.1X …7.5
- CVE-2026-21909A Missing Release of Memory after Effective Lifetime vulnera…7.1
- CVE-2026-2191A weakness has been identified in Tenda AC9 15.03.06.42_mult…7.3
- CVE-2026-21910An Improper Check for Unusual or Exceptional Conditions vuln…7.1
- CVE-2026-21911An Incorrect Calculation vulnerability in the Layer 2 Contro…7.1
- CVE-2026-21913An Incorrect Initialization of Resource vulnerability in the…8.7
- CVE-2026-21914An Improper Locking vulnerability in the GTP plugin of Junip…8.7
- CVE-2026-21915A Permissive List of Allowed Input vulnerability in the CLI …8.4
- CVE-2026-21916A UNIX Symbolic Link (Symlink) Following vulnerability in th…7.3
- CVE-2026-21917An Improper Validation of Syntactic Correctness of Input vul…8.7
- CVE-2026-21918A Double Free vulnerability in the flow processing daemon (f…8.7
Are you affected by CVE-2026-21912?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
