Vulnerability record · CVE-2025-21590 · published 12 March 2025
CVE-2025-21590: Juniper Junos OS kernel improper isolation allows local code injection
Juniper · Junos
Junos OS contains an improper isolation or compartmentalization flaw in the kernel that lets a local attacker with shell access inject arbitrary code. Because the injected code runs in the kernel context, it can compromise the integrity of the affected device. The issue is not reachable from the Junos CLI.
Description
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device. This issue is not exploitable from the Junos CLI. This issue affects Junos OS: * All versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S10, * 22.2 versions before 22.2R3-S6, * 22.4 versions before 22.4R3-S6, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R1-S2, 24.2R2.
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityCISA KEV listing indicates known exploitation, but the flaw requires local shell access with high privileges and has medium CVSS severity.
What it is
Junos OS contains an improper isolation or compartmentalization flaw in the kernel that lets a local attacker with shell access inject arbitrary code. Because the injected code runs in the kernel context, it can compromise the integrity of the affected device. The issue is not reachable from the Junos CLI.
Impact
An attacker who already holds high privileges and shell access can execute arbitrary code in the kernel, undermining device integrity. The CVSS vector shows high integrity impact only, with no confidentiality or availability impact.
Attack surface
Reached locally via the shell, not through the Junos CLI or network services. It requires high privileges (PR:H) and no user interaction (UI:N).
Exploitation
CVE-2025-21590 is listed in CISA KEV with a due date of 2025-04-03, indicating known exploitation, though EPSS 30-day probability is low at 0.01715. No ransomware campaign use is documented.
What to do
- Upgrade Junos OS to a fixed release: 21.2R3-S9 or later, 21.4R3-S10 or later, 22.2R3-S6 or later, 22.4R3-S6 or later, 23.2R2-S3 or later, 23.4R2-S4 or later, or 24.2R1-S2 or 24.2R2 or later.
- Apply the vendor mitigations in Juniper advisory JSA93446 if immediate upgrade is not possible.
- Restrict shell access to trusted administrators and audit accounts with high privileges.
- Follow CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
Detection
- Monitor for unexpected kernel-level code injection or anomalous process behavior on Junos devices.
- Audit shell access logs for high-privilege accounts and unusual command execution.
- Review Juniper advisory JSA93446 and CISA KEV guidance for indicators associated with this vulnerability.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-21590 to the Known Exploited Vulnerabilities catalog on 13 March 2025 as "Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 April 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers | Third Party Advisory |
| https://supportportal.juniper.net/JSA93446 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-21590 | US Government Resource |
Track CVE-2025-21590 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-21590), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.