CVE-2025-30650
Juniper Junos
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: * MPC7, MPC8, MPC9, MPC10, MPC11 * LC2101, LC2103 * LC480, LC4800, LC9600 * MX304 (built-in FPC) * MX-SPC3 * SRX5K-SPC3 * EX9200-40XS * FPC3-PTX-U2, FPC3-PTX-U3 * FPC3-SFF-PTX * LC1101, LC1102, LC1104, LC1105 This issue affects Junos OS: * all versions before 22.4R3-S8, * from 23.2 before 23.2R2-S6, * from 23.4 before 23.4R2-S6, * from 24.2 before 24.2R2-S3, * from 24.4 before 24.4R2, * from 25.2 before 25.2R2.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an administrative account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 6.7 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H- CVSS v4
- 8.4
- Weakness
- CWE-306
- Assigned by
- sirt@juniper.net
Dates
- Published
- 2026-04-08
- Last modified
- 2026-08-26
- Sources
- NVD
Affected products
- Juniper Junos- 22.4, 22.4, 23.2, 23.4, 24.2, 25.2
- Juniper Ex9200all versions
- Juniper Fpc3-Ptx-U2all versions
- Juniper Fpc3-Ptx-U3all versions
- Juniper Fpc3-Sff-Ptxall versions
- Juniper Lc1101all versions
- Juniper Lc1102all versions
- Juniper Lc1104all versions
- Juniper Lc1105all versions
- Juniper Lc2101all versions
- Juniper Lc2103all versions
- Juniper Lc480all versions
As listed in the NVD configuration data. Not a statement about your estate.