Juniper Networks Default Credential Vulnerability Allows Unauthorized Full Access
ID: ce6658f7-7811-5396-b723-07ba8fc2fac4
STIX ID: report--ce6658f7-7811-5396-b723-07ba8fc2fac4
Feed Name: GBHackers
Juniper Networks has disclosed a critical default-credential vulnerability (CVE-2026-33784) in Support Insights Virtual Lightweight Collector (vLWC) prior to release 3.0.94 with a CVSS v3.1 score of 9.8; an attacker on the same network can log in with the unchanged factory password to obtain full administrative control. Juniper recommends upgrading to vLWC 3.0.94 or later to remediate the provisioning flaw, and as a temporary mitigation advises manually changing the default password; the vendor reports no current evidence of exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
