Junos OS - RCE (CVE-2023-36845)
91Exploiting IPs reported
A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to remotely execute code.
CrowdSec analysis
CVE-2023-36845 is a critical vulnerability impacting the J-Web interface of Juniper Networks Junos OS, allowing unauthenticated remote code execution through a crafted PHP environment variable modification.
CrowdSec has been tracking this vulnerability and its exploits since 1st of April 2025.
Data from the CrowdSec community indicates that exploitation of CVE-2023-36845 is highly selective and intelligence-driven. Threat actors use advanced reconnaissance and carefully choose their targets, often as part of sophisticated campaigns or advanced persistent threat operations. CrowdSec network telemetry also shows that exploitation of CVE-2023-36845 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threat landscapes.
Observed exploitation attempts commonly leverage URLs containing /?phprc=/dev/fd/0
.
Exploitation
Get real-time information about exploitation attempts and actors involved.
Protection
Find out relevant information to protect your stack against this CVE.
Blocklist
With our advanced worldwide network detection, CrowdSec can provide a list of IPs known for exploiting the vulnerability.
To increase your protection against this CVE, block exploitation attempts with this list of identified actors.