Critical Flaw in Juniper Routers Exposes Networks to Complete Takeover Attacks


Critical Security Vulnerability Patched in Juniper Networks Products

Juniper Networks has issued critical security updates addressing a severe vulnerability affecting their networking products. The flaw, identified as CVE-2025-21589, received a critical CVSS v3.1 score of 9.8 and CVS v4 score of 9.3.

The vulnerability affects multiple product lines including:
– Session Smart Router
– Session Smart Conductor
– WAN Assurance Router

This authentication bypass vulnerability could allow network-based attackers to gain unauthorized administrative control of affected devices. The issue impacts various versions of the affected products, specifically versions from 5.6.7 to 6.3.

Affected versions include:
– 5.6.7 through 5.6.17
– 6.0.8 and later
– 6.1 through 6.1.12-lts
– 6.2 through 6.2.8-lts
– 6.3 through 6.3.3-r2

The vulnerability has been patched in the following versions:
– SSR-5.6.17
– SSR-6.1.12-lts
– SSR-6.2.8-lts
– SSR-6.3.3-r2

Juniper Networks discovered the flaw during internal security testing and reports no known malicious exploitation. Devices operating with WAN Assurance connected to Mist Cloud have received automatic patches, though upgrading to the latest version is still recommended.

Share This Article