Skip to content

Juniper CVE-2024-21591 (unauth buffer overflow) - #21800

Open
h00die wants to merge 7 commits into
rapid7:masterfrom
h00die:juniper_cve_2024_21591
Open

Juniper CVE-2024-21591 (unauth buffer overflow)#21800
h00die wants to merge 7 commits into
rapid7:masterfrom
h00die:juniper_cve_2024_21591

Conversation

@h00die

@h00die h00die commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Description

This PR adds an exploit for CVE-2024-21591, a stack based buffer overflow on Juniper devices. While there was a DoS PoC given (see web archive URL in references), this seems to be the first exploit resulting in a shell I've seen. That being said, the stack is going to be dependent on device and firmware, so that isn't a surprise.

Breaking Changes

None

Reviewer Notes

pcap emailed to msfdev@metasploit.com

Verification Steps

see pcap

Test Evidence

see pcap

AI Usage Disclosure

GLM-5.3 was used in development

@h00die
h00die marked this pull request as ready for review September 3, 2026 18:23
@h00die h00die changed the title working but ugly: juniper cve-2024-21591 Juniper CVE-2024-21591 (unauth buffer overflow) Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

1 participant