#VU113056 Incorrect authorization in Juniper Junos OS - CVE-2025-6549
Published: July 18, 2025
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to incorrect authorization error in the web server. A remote non-authenticated attacker can reach the Juniper Web Device Manager (J-Web).
When Juniper Secure connect (JSC) is enabled on specific interfaces, or multiple interfaces are configured for J-Web, the J-Web UI is reachable over more than the intended interfaces.