Junglewise Threat Intelligence

CVE-2025-21590: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

CVE-2025-21590 · Severity: critical · CVSS 6.7 · Exploited in the wild · Published 2025-03-13

Technologies: Juniper Junos OS. Vendors: Juniper, Juniper Networks.

Executive brief

An improper isolation vulnerability in the Juniper Junos OS kernel allows a local attacker with high privileges and shell access to inject arbitrary code. The vulnerability cannot be exploited via the Junos CLI but can lead to a full compromise of device integrity.

Affected products

  • Juniper Networks Junos OS All versions before 21.2R3-S9, 21.4 versions before 21.4R3-S10, 22.2 versions before 22.2R3-S6, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R1-S2, 24.2R2

Timeline

  • 2025-03-12: disclosed: New CVE received from Juniper Networks
  • 2025-03-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-13: exploited: Reported as exploited in the wild by CISA and Google Cloud/Mandiant blog

Related threats