cbcvebase.
CVE-2025-21590
published 2025-03-12

CVE-2025-21590: An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to…

PriorityP178medium4.4CVSS 3.1
AVLACLPRHUINSUCNIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-04-03
Exploited in the wild
EPSS
1.66%
74.0th percentile
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device.

A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device.
This issue is not exploitable from the Junos CLI.
This issue affects Junos OS:


* All versions before 21.2R3-S9,
* 21.4 versions before 21.4R3-S10,
* 22.2 versions before 22.2R3-S6,
* 22.4 versions before 22.4R3-S6,
* 23.2 versions before 23.2R2-S3,
* 23.4 versions before 23.4R2-S4,
* 24.2 versions before 24.2R1-S2, 24.2R2.

Affected

16 ranges
VendorProductVersion rangeFixed in
juniperjunos<= 21.2
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos_os
juniper_networksjunos_os< 21.2R3-S921.2R3-S9
juniper_networksjunos_os>= 21.4 < 21.4R3-S1021.4R3-S10
juniper_networksjunos_os>= 22.2 < 22.2R3-S622.2R3-S6
juniper_networksjunos_os>= 22.4 < 22.4R3-S622.4R3-S6
juniper_networksjunos_os>= 23.2 < 23.2R2-S323.2R2-S3
juniper_networksjunos_os>= 23.4 < 23.4R2-S423.4R2-S4
juniper_networksjunos_os>= 24.2 < 24.2R1-S2, 24.2R224.2R1-S2, 24.2R2

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation requires local shell access (not Junos CLI); monitor for unexpected shell sessions or process execution originating from the shell on Junos OS devices, particularly on NFX-Series, Virtual SRX, SRX-Series Branch, SRX-Series HE, EX-Series, QFX-Series, ACX, and MX-Series devices.
  • Hunt for TINYSHELL-based backdoors on Juniper Junos OS routers; UNC3886 deployed multiple TINYSHELL variants with distinct C2 communication methods and hardcoded C2 server addresses.
  • All six backdoors deployed in this campaign used distinct C2 communication methods and separate hardcoded C2 server addresses — threat hunting should focus on anomalous outbound connections from Junos OS routers to unknown external IPs.
  • Restrict shell access to trusted users only as an immediate mitigation while patching; audit all accounts with shell-level access on Junos OS devices.
  • ·The vulnerability is only exploitable from the OS shell, not from the Junos CLI; detection and access-control efforts should focus on shell-level access rather than CLI-based controls.
  • ·The complete list of affected/resolved platforms is still under investigation by Juniper at time of advisory publication; assume all Junos OS device families are potentially affected until confirmed otherwise.

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv4.06.7MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck6.7MEDIUM
cisa6.7MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.