logo

The “Open Door” Vulnerability: Unchanged Default Passwords Put Juniper vLWC at Risk

ID: fdcf467b-be83-5e50-9be5-4f2e3ebcc1ba

STIX ID: report--fdcf467b-be83-5e50-9be5-4f2e3ebcc1ba

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Juniper disclosed CVE-2026-33784, a critical (CVSS 9.8) vulnerability in its Support Insights Virtual Lightweight Collector (vLWC) where images ship with a high-privileged default password that is not forced to be changed during provisioning, allowing unauthenticated remote attackers to gain full control; versions prior to 3.0.94 are affected and Juniper has released 3.0.94 to enforce secure password management, with administrators advised to update or manually change the setup password.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.