VendorsJuniperjunos25.2
Vulnerabilities

Juniper Junos 25.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

30CVEs
CVE-2026-33785
Junos OS: MX Series: Missing Authorization for specific 'request' CLI commands in a JDM/CSDS scenario
Published 2026-04-09 · Analyzed
8.8EPSS 0.001
CVE-2026-21906
Junos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.006
CVE-2026-57023
Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash
Published 2026-07-09 · Analyzed
8.7EPSS 0.005
CVE-2026-57026
Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
Published 2026-07-09 · Analyzed
8.7EPSS 0.005
CVE-2026-21905
Junos OS: SRX Series, MX Series with MX-SPC3 or MS-MPC: Receipt of multiple specific SIP messages results in flow management process crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2026-21913
Junos OS: EX4000: A high volume of traffic destined to the device leads to a crash and restart
Published 2026-01-15 · Analyzed
8.7EPSS 0.004
CVE-2026-33778
Junos OS: SRX Series, MX Series: When a specifically malformed first ISAKMP packet is received kmd/iked crashes
Published 2026-04-09 · Analyzed
8.7EPSS 0.003
CVE-2026-33790
Junos OS: SRX Series: In a NAT64 configuration, receipt of a specific, malformed ICMPv6 packet will cause the srxpfe process to crash and restart.
Published 2026-04-09 · Analyzed
8.7EPSS 0.003
CVE-2026-21914
Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash
Published 2026-01-15 · Analyzed
8.7EPSS 0.003
CVE-2026-33791
Junos OS and Junos OS Evolved: Execution of crafted CLI commands allows for arbitrary shell injection as root
Published 2026-04-09 · Modified
8.4EPSS 0.007
CVE-2025-30650
Junos OS: Privileged local user can gain access to a Linux-based FPC as root
Published 2026-04-08 · Analyzed
8.4EPSS 0.001
CVE-2026-33779
Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
Published 2026-04-09 · Analyzed
8.3EPSS 0.001
CVE-2026-57030
Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS
Published 2026-07-09 · Analyzed
8.2EPSS 0.004
CVE-2026-21908
Junos OS and Junos OS Evolved: Use after free vulnerability In 802.1X authentication daemon can cause crash of the dot1xd process
Published 2026-01-15 · Analyzed
7.5EPSS 0.003
CVE-2025-59960
Junos OS and Junos OS Evolved: DHCP Option 82 messages from clients being passed unmodified to the DHCP server
Published 2026-01-15 · Analyzed
7.4EPSS 0.003
CVE-2026-33797
Junos OS and Junos OS Evolved: An attacker sending a specific genuine BGP packet causes a BGP reset
Published 2026-04-09 · Modified
7.4EPSS 0.002
CVE-2026-21916
Junos OS: A low privileged user can escalate their privileges so that they can login as root
Published 2026-04-09 · Analyzed
7.3EPSS 0.001
CVE-2026-33801
Junos OS and Junos OS Evolved: When a specifically malformed BGP route update is received RPD crashes
Published 2026-07-09 · Analyzed
7.1EPSS 0.003
CVE-2026-33800
Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause an FPC crash
Published 2026-07-09 · Analyzed
7.1EPSS 0.003
CVE-2026-57019
Junos OS: MX Series: Specific traffic causes an FPC to reset
Published 2026-07-09 · Analyzed
7.1EPSS 0.003
CVE-2026-33775
Junos OS: MX Series: Mismatch between configured and received packet types causes memory leak in bbe-smgd
Published 2026-04-09 · Analyzed
7.1EPSS 0.002
CVE-2026-33781
Junos OS: EX Series, QFX Series: In a VXLAN scenario when specific control protocol packets are received, memory leaks and eventually no traffic is passed
Published 2026-04-09 · Analyzed
7.1EPSS 0.002
CVE-2026-57021
Junos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crash
Published 2026-07-09 · Analyzed
6.9EPSS 0.005
CVE-2026-57024
Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
Published 2026-07-09 · Analyzed
6.9EPSS 0.004
CVE-2026-57054
Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
Published 2026-07-09 · Analyzed
6.9EPSS 0.004
CVE-2025-59961
Junos OS and Junos OS Evolved: Unix socket used to control the jdhcpd process is world-writable
Published 2026-01-15 · Analyzed
6.8EPSS 0.001
CVE-2026-33802
Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command
Published 2026-07-09 · Analyzed
6.8EPSS 0.001
CVE-2026-33787
Junos OS: SRX1500, SRX4100, SRX4200, SRX4600: When a specific show command is executed chassisd crashes
Published 2026-04-09 · Analyzed
6.8EPSS 0.001
CVE-2026-33776
Junos OS and Junos OS Evolved: Specific low privileged CLI command exposes sensitive information
Published 2026-04-09 · Analyzed
6.8EPSS 0.001
CVE-2026-57031
Junos OS: MX Series: For subscribers configured on static interfaces, input filters are not in effect
Published 2026-07-09 · Analyzed
5.3EPSS 0.002