Ui discrepancy for security feature in Junos OS - CVE-2025-52983

 

Ui discrepancy for security feature in Junos OS - CVE-2025-52983

Published: July 18, 2025


Vulnerability identifier: #VU113062
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-52983
CWE-ID: CWE-446
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to execute arbitrary code.

The vulnerability exists due to ui discrepancy for security feature error in the UI. A remote privileged user can access the device.

On VM Host Routing Engines (RE), even if the configured public key for root has been removed, remote users which are in possession of the corresponding private key can still log in as root.


Affected software

Junos OS

How to mitigate CVE-2025-52983

Install updates from vendor's website.

Junos OS - addressed in versions 22.2R3-S7, 22.4R3-S5, 23.2R2-S3, 23.4R2-S3, 24.2R1-S2, 24.2R2, 24.4R1

External References

Related Security Bulletins