CVE-2025-30650
Received
Received - Intake
Missing Authentication in Junos OS Line Cards Allows Root Access
Publication date: 2026-04-08
Last updated on: 2026-04-13
Assigner: Juniper Networks, Inc.
Description
Description
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.
This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include:
* MPC7, MPC8, MPC9, MPC10, MPC11
* LC2101, LC2103
* LC480, LC4800, LC9600
* MX304 (built-in FPC)
* MX-SPC3
* SRX5K-SPC3
* EX9200-40XS
* FPC3-PTX-U2, FPC3-PTX-U3
* FPC3-SFF-PTX
* LC1101, LC1102, LC1104, LC1105
This issue affects Junos OS:
* all versions before 22.4R3-S8,
* from 23.2 before 23.2R2-S6,
* from 23.4 before 23.4R2-S6,
* from 24.2 before 24.2R2-S3,
* from 24.4 before 24.4R2,
* from 25.2 before 25.2R2.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| juniper | junos_os | to 22.4R3-S8 (exc) |
| juniper | junos_os | From 23.2 (inc) to 23.2R2-S6 (exc) |
| juniper | junos_os | From 23.4 (inc) to 23.4R2-S6 (exc) |
| juniper | junos_os | From 24.2 (inc) to 24.2R2-S3 (exc) |
| juniper | junos_os | From 24.4 (inc) to 24.4R2 (exc) |
| juniper | junos_os | From 25.2 (inc) to 25.2R2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |