Improper Check for Exceptional Conditions in Junos OS DHCP Service by Juniper Networks
CVE-2025-59960
6.3MEDIUM
Key Information:
- Vendor
Juniper Networks
- Status
- Vendor
- CVE Published:
- 15 January 2026
Badges
👾 Exploit Exists
What is CVE-2025-59960?
An improper check in the Juniper DHCP service allows a DHCP client in one subnet to deplete address pools of other subnets, resulting in Denial of Service (DoS) for users relying on those pools. When the DHCP relay agent processes client requests in 'forward-only' mode with Option 82, it should reject certain packets unless 'trust-option82' is explicitly enabled. Instead, it forwards these non-compliant requests, leading to unintended exhaustion of the DHCP server’s address pool. This vulnerability affects various versions of Junos OS and Junos OS Evolved, creating significant risks for network availability and reliability.
Affected Version(s)
Junos OS 0 < 21.2R3-S10
Junos OS 21.4 < 21.4R3-S12
Junos OS 22.2 < 22.2*