Juniper Security Updates – 12 February 2025

Juniper has released security updatesto fix a critical vulnerability affectingmultiple Juniper Networks products.

The addressed vulnerability could allow the remote attacker to bypass authentication and take administrative control of the affected systems.

Juniper Networks API Authentication Bypass Vulnerability (CVE-2025-21589):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

The affected products:

  • Juniper Session Smart Router.
  • Juniper Session Smart Conductor.
  • Juniper WAN Assurance Managed Router.
Vulnerabilities

CVE-2025-21589

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Juniper Security Advisory

References