Incorrect Permission Assignment Vulnerability in Juniper Networks Junos OS
CVE-2025-30661

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
11 July 2025

Badges

👾 Exploit Exists

What is CVE-2025-30661?

A vulnerability exists in the script processing of Juniper Networks' Junos OS that allows a local, low-privileged user to perform actions typically reserved for higher privileges. By exploiting this flaw, a user with access to the local file system can craft a script to be executed as root during system boot, resulting in potential complete control over the affected system. Specific line cards are impacted by this issue, which arises in versions of Junos OS from 23.2 before 23.2R2-S4, 23.4 before 23.4R2-S5, 24.2 before 24.2R2-S1, and from 24.4 before 24.4R1-S3 and 24.4R2. Systems running versions earlier than 23.1R2 are not affected.

Affected Version(s)

Junos OS 23.2 < 23.2R2-S4

Junos OS 23.4 < 23.4R2-S5

Junos OS 24.2 < 24.2R2-S1

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Juniper SIRT would like to acknowledge and thank Pierre EMERIAUD from Orange group & Orange CERT-CC for responsibly reporting this vulnerability.
.
CVE-2025-30661 : Incorrect Permission Assignment Vulnerability in Juniper Networks Junos OS