Improper authentication in Juniper Networks, Inc. products - CVE-2025-21589
Published: February 12, 2025
Vulnerability identifier: #VU103903
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-21589
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an unspecified error in the authentication process. A remote non-authenticated attacker can bypass authentication and gain administrative access to the device.
Affected software
Session Smart Router
WAN Assurance Router
Session Smart Conductor
WAN Assurance Router
Session Smart Conductor
How to mitigate CVE-2025-21589
Install updates from vendor's website.
Session Smart Router - addressed in versions 5.6.17, 6.1.12, 6.2.8, 6.3.3-r2
WAN Assurance Router - addressed in versions 5.6.17, 6.1.12, 6.2.8, 6.3.3-r2
Session Smart Conductor - addressed in versions 5.6.17, 6.1.12, 6.2.8, 6.3.3-r2
WAN Assurance Router - addressed in versions 5.6.17, 6.1.12, 6.2.8, 6.3.3-r2
Session Smart Conductor - addressed in versions 5.6.17, 6.1.12, 6.2.8, 6.3.3-r2