Incorrect permission assignment for critical resource in Junos OS and Junos OS Evolved - CVE-2025-59961

 

Incorrect permission assignment for critical resource in Junos OS and Junos OS Evolved - CVE-2025-59961

Published: January 20, 2026


Vulnerability identifier: #VU121681
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59961
CWE-ID: CWE-732
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to manipulate data.

The vulnerability exists due to incorrect permission assignment for critical resource error in the Juniper DHCP daemon (jdhcpd). A local user can write to the Unix socket used to manage the jdhcpd process, resulting in complete control over the resource.


Affected software

Junos OS
Junos OS Evolved

How to mitigate CVE-2025-59961

Install updates from vendor's website.

Junos OS - addressed in versions 21.2R3-S10, 22.4R3-S8, 23.2R2-S5, 23.4R2-S6, 24.2R2-S2, 24.4R2, 25.2R1-S1, 25.2R2, 25.4R1
Junos OS Evolved - addressed in versions 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-S6-EVO, 24.2R2-S2-EVO, 24.4R2-EVO, 25.2R1-S1-EVO, 25.2R2-EVO, 25.4R1-EVO

External References

Related Security Bulletins