CVE-2025-52954
Last modified
CVE-2025-52954 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain root privileges, leading to a system compromise. Any low-privileged user with the capability to send packets over the internal VRF can execute arbitrary Junos commands and modify the configuration, and thus compromise the system. This issue affects Junos OS Evolved: * All versions before 22.2R3-S7-EVO, * from 22.4 before 22.4R3-S7-EVO, * from 23.2 before 23.2R2-S4-EVO, * from 23.4 before 23.4R2-S5-EVO, * from 24.2 before 24.2R2-S1-EVO * from 24.4 before 24.4R1-S2-EVO, 24.4R2-EVO.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain root privileges, leading to a system compromise. Any low-privileged user with the capability to send packets over the internal VRF can execute arbitrary Junos commands and modify the configuration, and thus compromise the system. This issue affects Junos OS Evolved: * All versions before 22.2R3-S7-EVO, * from 22.4 before 22.4R3-S7-EVO, * from 23.2 before 23.2R2-S4-EVO, * from 23.4 before 23.4R2-S5-EVO, * from 24.2 before 24.2R2-S1-EVO * from 24.4 before 24.4R1-S2-EVO, 24.4R2-EVO.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos Os Evolved | < 22.2 |
| Juniper | Junos Os Evolved | 22.2 |
| Juniper | Junos Os Evolved | 22.4 |
| Juniper | Junos Os Evolved | 23.2 |
| Juniper | Junos Os Evolved | 23.4 |
| Juniper | Junos Os Evolved | 24.2 |
| Juniper | Junos Os Evolved | 24.4 |
References
- https://supportportal.juniper.net/JSA100060Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-52954?
How severe is CVE-2025-52954?
How do I fix CVE-2025-52954?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-52949An Improper Handling of Length Parameter Inconsistency vulne…7.1
- CVE-2025-5295A vulnerability classified as critical was found in FreeFloa…9.8
- CVE-2025-52950A Missing Authorization vulnerability in Juniper Networks Se…9.6
- CVE-2025-52951A Protection Mechanism Failure vulnerability in kernel filte…6.9
- CVE-2025-52952An Out-of-bounds Write vulnerability in the connectivity fau…7.1
- CVE-2025-52953An Expected Behavior Violation vulnerability in the routing …7.1
- CVE-2025-52955An Incorrect Calculation of Buffer Size vulnerability in the…7.1
- CVE-2025-52958A Reachable Assertion vulnerability in the routing protocol …6
- CVE-2025-5296CWE-59: Improper Link Resolution Before File Access ('Link F…7.3
- CVE-2025-52960A Buffer Copy without Checking Size of Input vulnerability i…8.2
- CVE-2025-52961An Uncontrolled Resource Consumption vulnerability in the Co…7.1
- CVE-2025-52963An Improper Access Control vulnerability in the User Interfa…6.8
Are you affected by CVE-2025-52954?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
