Vulnerability research · Demo
Juniper RCE — CVE-2023-36845
2025-02-01
Demo of CVE-2023-36845 — a PHP external variable modification flaw in Juniper J-Web (EX / SRX) that lets an unauthenticated attacker set PHPRC and achieve remote code execution.
Watch on YouTube →Juniper RCE — CVE-2023-36845
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code.
Using a crafted request that sets the PHPRC variable, an attacker can modify the PHP execution environment and inject executable code.
Watch: YouTube