Moslem Haghighian
Discoveries and Talk

Juniper RCE — CVE-2023-36845

Demo of CVE-2023-36845 — a PHP external variable modification flaw in Juniper J-Web (EX / SRX) that lets an unauthenticated attacker set PHPRC and achieve remote code execution.

Watch on YouTube →

Juniper RCE — CVE-2023-36845

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code.

Using a crafted request that sets the PHPRC variable, an attacker can modify the PHP execution environment and inject executable code.

Watch: YouTube