CVE-2025-6549
published 2025-07-11CVE-2025-6549: An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to…
medium6.9CVSS 4.0
AVNACLATNPRNUINVCLVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUYRUVXREMUX
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the
Juniper Web Device Manager
(J-Web).
When Juniper Secure connect (JSC) is enabled on specific interfaces, or multiple interfaces are configured for J-Web, the J-Web UI is reachable over more than the intended interfaces.
This issue affects Junos OS:
* all versions before 21.4R3-S9,
* 22.2 versions before 22.2R3-S5,
* 22.4 versions before 22.4R3-S5,
* 23.2 versions before 23.2R2-S3,
* 23.4 versions before 23.4R2-S5,
* 24.2 versions before 24.2R2.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | j-web | — | — |
| juniper | junos | < 21.4 | 21.4 |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | srx_series | — | — |
| juniper_networks | junos_os | < 21.4R3-S9 | 21.4R3-S9 |
| juniper_networks | junos_os | >= 22.2 < 22.2R3-S5 | 22.2R3-S5 |
| juniper_networks | junos_os | >= 22.4 < 22.4R3-S5 | 22.4R3-S5 |
| juniper_networks | junos_os | >= 23.2 < 23.2R2-S3 | 23.2R2-S3 |
| juniper_networks | junos_os | >= 23.4 < 23.4R2-S5 | 23.4R2-S5 |
| juniper_networks | junos_os | >= 24.2 < 24.2R2 | 24.2R2 |