← Vulnerability feed

Vulnerability record · CVE-2025-21590 · published 12 March 2025

CVE-2025-21590: Juniper Junos OS kernel improper isolation allows local code injection

Juniper · Junos

Junos OS contains an improper isolation or compartmentalization flaw in the kernel that lets a local attacker with shell access inject arbitrary code. Because the injected code runs in the kernel context, it can compromise the integrity of the affected device. The issue is not reachable from the Junos CLI.

6.7 CVSS 4.0 Medium CISA KEV since 13 Mar 2025 EPSS 1.7% · top 23.5% CWE-653 · CWE-653
6.7CVSS 4.0 base score
1.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device. This issue is not exploitable from the Junos CLI. This issue affects Junos OS:  * All versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S10,  * 22.2 versions before 22.2R3-S6,  * 22.4 versions before 22.4R3-S6,  * 23.2 versions before 23.2R2-S3,  * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R1-S2, 24.2R2.

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCISA KEV listing indicates known exploitation, but the flaw requires local shell access with high privileges and has medium CVSS severity.

What it is

Junos OS contains an improper isolation or compartmentalization flaw in the kernel that lets a local attacker with shell access inject arbitrary code. Because the injected code runs in the kernel context, it can compromise the integrity of the affected device. The issue is not reachable from the Junos CLI.

Impact

An attacker who already holds high privileges and shell access can execute arbitrary code in the kernel, undermining device integrity. The CVSS vector shows high integrity impact only, with no confidentiality or availability impact.

Attack surface

Reached locally via the shell, not through the Junos CLI or network services. It requires high privileges (PR:H) and no user interaction (UI:N).

Exploitation

CVE-2025-21590 is listed in CISA KEV with a due date of 2025-04-03, indicating known exploitation, though EPSS 30-day probability is low at 0.01715. No ransomware campaign use is documented.

What to do

  • Upgrade Junos OS to a fixed release: 21.2R3-S9 or later, 21.4R3-S10 or later, 22.2R3-S6 or later, 22.4R3-S6 or later, 23.2R2-S3 or later, 23.4R2-S4 or later, or 24.2R1-S2 or 24.2R2 or later.
  • Apply the vendor mitigations in Juniper advisory JSA93446 if immediate upgrade is not possible.
  • Restrict shell access to trusted administrators and audit accounts with high privileges.
  • Follow CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable.

Detection

  • Monitor for unexpected kernel-level code injection or anomalous process behavior on Junos devices.
  • Audit shell access logs for high-privilege accounts and unusual command execution.
  • Review Juniper advisory JSA93446 and CISA KEV guidance for indicators associated with this vulnerability.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-21590 to the Known Exploited Vulnerabilities catalog on 13 March 2025 as "Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 April 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-21590 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-36845Juniper Junos OS J-Web PHP variable modification RCEJ-Web in Junos OS on EX Series and SRX Series mishandles the PHP PHPRC environment variable, letting a crafted request alter the PHP execution enviro…KEVEPSS 95%analysed9.8CVE-2020-1631Juniper Junos OS J-Web HTTP service path traversal and local file inclusionThe HTTP/HTTPS service behind J-Web, Web Authentication, Dynamic-VPN, Firewall Authentication Pass-Through with Web-Redirect, and ZTP in Junos OS doe…KEVEPSS 4.8%analysed5.3CVE-2023-36851Juniper Junos OS SRX J-Web missing authentication allows file upload/downloadJunos OS on SRX Series exposes webauth_operation.php without authentication, letting a network attacker upload and download arbitrary files through J…KEVEPSS 1.1%analysed5.3CVE-2023-36844Juniper Junos OS EX Series J-Web PHP Environment Variable ModificationJ-Web on Junos OS for EX Series fails to properly restrict external PHP variable modification, letting an unauthenticated network attacker alter impo…KEVEPSS 90%analysed5.3CVE-2023-36846Juniper Junos OS SRX J-Web Missing Authentication Allows File UploadJunos OS on SRX Series fails to require authentication for a critical function in user.php reachable through J-Web, letting an unauthenticated networ…KEVEPSS 93%analysed5.3CVE-2023-36847Juniper Junos OS EX Series J-Web installAppPackage.php missing authenticationJunos OS on EX Series exposes installAppPackage.php through J-Web without requiring authentication. An unauthenticated network attacker can upload ar…KEVEPSS 83%analysed10.0CVE-2021-31384Juniper junos improper authorization vulnerabilityDue to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in …EPSS 1.2%10.0CVE-2021-0248Juniper junos hard-coded credentials vulnerabilityThis issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an …EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2025-21590), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.