Use of Incorrect Operator Vulnerability in Juniper Networks Junos OS Evolved Firewall
CVE-2025-52985
Key Information:
- Vendor
Juniper Networks
- Status
- Vendor
- CVE Published:
- 11 July 2025
Badges
What is CVE-2025-52985?
A vulnerability exists within the Routing Engine firewall of Juniper Networks' Junos OS Evolved that can allow an unauthenticated network attacker to bypass security restrictions. Specifically, when a firewall filter applied to the lo0 or re:mgmt interface references a prefix list with 'from prefix-list', the filter fails to match if the list exceeds 10 entries. This flaw affects both IPv4 and IPv6 traffic, allowing packets to evade filtering under certain configurations, posing significant security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Junos OS Evolved 23.2R2-S3-EVO < 23.2R2-S4-EVO
Junos OS Evolved 23.4R2-S3-EVO < 23.4R2-S5-EVO
Junos OS Evolved 24.2R2-EVO < 24.2R2-S1-EVO
References
CVSS V4
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved