CVE-2025-21590
published 2025-03-12CVE-2025-21590: An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to…
PriorityP178medium4.4CVSS 3.1
AVLACLPRHUINSUCNIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-04-03
Exploited in the wild
EPSS
1.66%
74.0th percentile
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device. This issue is not exploitable from the Junos CLI. This issue affects Junos OS: * All versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S10, * 22.2 versions before 22.2R3-S6, * 22.4 versions before 22.4R3-S6, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R1-S2, 24.2R2.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | <= 21.2 | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper_networks | junos_os | < 21.2R3-S9 | 21.2R3-S9 |
| juniper_networks | junos_os | >= 21.4 < 21.4R3-S10 | 21.4R3-S10 |
| juniper_networks | junos_os | >= 22.2 < 22.2R3-S6 | 22.2R3-S6 |
| juniper_networks | junos_os | >= 22.4 < 22.4R3-S6 | 22.4R3-S6 |
| juniper_networks | junos_os | >= 23.2 < 23.2R2-S3 | 23.2R2-S3 |
| juniper_networks | junos_os | >= 23.4 < 23.4R2-S4 | 23.4R2-S4 |
| juniper_networks | junos_os | >= 24.2 < 24.2R1-S2, 24.2R2 | 24.2R1-S2, 24.2R2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation requires local shell access (not Junos CLI); monitor for unexpected shell sessions or process execution originating from the shell on Junos OS devices, particularly on NFX-Series, Virtual SRX, SRX-Series Branch, SRX-Series HE, EX-Series, QFX-Series, ACX, and MX-Series devices. ↗
- →Hunt for TINYSHELL-based backdoors on Juniper Junos OS routers; UNC3886 deployed multiple TINYSHELL variants with distinct C2 communication methods and hardcoded C2 server addresses. ↗
- →All six backdoors deployed in this campaign used distinct C2 communication methods and separate hardcoded C2 server addresses — threat hunting should focus on anomalous outbound connections from Junos OS routers to unknown external IPs. ↗
- →Restrict shell access to trusted users only as an immediate mitigation while patching; audit all accounts with shell-level access on Junos OS devices. ↗
- ·The vulnerability is only exploitable from the OS shell, not from the Junos CLI; detection and access-control efforts should focus on shell-level access rather than CLI-based controls. ↗
- ·The complete list of affected/resolved platforms is still under investigation by Juniper at time of advisory publication; assume all Junos OS device families are potentially affected until confirmed otherwise. ↗
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv4.06.7MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck6.7MEDIUM
cisa6.7MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jwv5-xmf5-mp56: An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to
ghsa_unreviewed·2025-03-12
CVE-2025-21590 [MEDIUM] CWE-653 GHSA-jwv5-xmf5-mp56: An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device.
A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device.
This issue is not exploitable from the Junos CLI.
This issue affects Junos OS:
* All versions before 21.2R3-S9,
* 21.4 versions before 21.4R3-S10,
* 22.2 versions before 22.2R3-S6,
* 22.4 versions before 22.4R3-S6,
* 23.2 versions before 23.2R2-S3,
* 23.4 versions before 23.4R2-S4,
* 24.2 versions before 24.2R1-S2, 24.2R2.
VulnCheck
Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
vulncheck·2025·CVSS 6.7
CVE-2025-21590 [MEDIUM] CWE-653 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.
Affected: Juniper Junos OS
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers; https://supportportal.juniper.net/s/article/2025-03-Reference-Advisory-The-RedPenguin-Malware-Incident; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://sup
CISA
Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
cisa·2025-03-13·CVSS 6.7
CVE-2025-21590 [MEDIUM] CWE-653 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
Vulnerability: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
Affected: Juniper Junos OS
Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2025-21590
Remediation Due Date: 2025-04-03
Juniper
CVE-2025-21590: An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to
vendor_juniper·2025-03-12·CVSS 4.4
CVE-2025-21590 [MEDIUM] CWE-653 CVE-2025-21590: An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to
CVE-2025-21590: An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device.
A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device.
This issue is not exploitable from the Junos CLI.
This issue affects Junos OS:
* All versions before 21.2R3-S9,
* 21.4 versions before 21.4R3-S10,
* 22.2 versions before 22.2R3-S6,
* 22.4 versions before 22.4R3-S6,
* 23.2 versions before 23.2R2-S3,
* 23.4 versions before 23.4R2-S4,
* 24.2 versions before 24.2R1-S2, 24.2R2.
CISA KEV: Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker wi
No detection rules found.
No public exploits indexed.
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
Threat Intelligence
# Look What You Made Us Patch: 2025 Zero-Days in Review
March 5, 2026
##### Google Threat Intelligence Group
##### Google Threat Intelligence
Visibility and context on the threats that matter most.
Contact Us & Get a Demo
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
### Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
## Look What You Made Us Patch: 2025 Zero-Days in Review
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
## Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first identified in 2024, toward increased enterprise exploitation. Both
Bleepingcomputer
Juniper patches bug that let Chinese cyberspies backdoor routers
blogs_bleepingcomputer·2025-03-13·CVSS 6.7
CVE-2025-21590 [MEDIUM] Juniper patches bug that let Chinese cyberspies backdoor routers
## Juniper patches bug that let Chinese cyberspies backdoor routers
## Sergiu Gatlan
Juniper Networks has released emergency security updates to patch a Junos OS vulnerability exploited by Chinese hackers to backdoor routers for stealthy access.
This medium severity flaw ( CVE-2025-21590 ) was reported by Amazon security engineer Matteo Memelli and is caused by an improper isolation or compartmentalization weakness. Successful exploitation lets local attackers with high privileges execute arbitrary code on vulnerable routers to compromise the devices' integrity.
"At least one instance of malicious exploitation (not at Amazon) has been reported to the Juniper SIRT. Customers are encouraged to upgrade to a fixed release as soon as it's available and in the meantime take steps to mitigat
2025-03-12
Published
2025-03-13
Added to CISA KEV
Exploited in the wild