Junglewise Threat Intelligence

CVE-2025-30650: Juniper Networks Junos OS privilege escalation in Linux-based line cards

CVE-2025-30650 · Severity: medium · CVSS 6.7 · Published 2026-04-08

Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks Junos OS could allow a high-privileged local user to gain full administrative (root) control over specific hardware components known as line cards. These line cards are responsible for processing network traffic in high-performance routers and switches. If exploited, an attacker could gain persistent access to the device, potentially leading to complete system compromise and the ability to intercept or disrupt network operations.

Technical details

A Missing Authentication for Critical Function vulnerability (CWE-306) exists in the command processing of Juniper Networks Junos OS. A local attacker with high privileges (specifically 'shell' and 'maintenance' permissions) can exploit this flaw to launch scripts during the boot-up sequence of Linux-based Flexible PIC Concentrators (FPCs). This allows the attacker to bypass standard authentication and escalate privileges to root on the line card. Once root access is achieved on the FPC, the attacker may gain full root access to the entire router with persistence, as these environments often lack Veriexec or robust accounting. Affected hardware includes various MPC and LC series line cards used in MX, SRX, EX, and PTX series devices. Patches are available in Junos OS versions 22.4R3-S8, 23.2R2-S6, 23.4R2-S6, 24.2R2-S3, 24.4R2, 25.2R2, and 25.4R1.

Affected products

  • Juniper Networks Junos OS All versions before 22.4R3-S8; 23.2 before 23.2R2-S6; 23.4 before 23.4R2-S6; 24.2 before 24.2R2-S3; 24.4 before 24.4R2; 25.2 before 25.2R2

Timeline

  • 2025-03-18: other: Vulnerability reported to vendor
  • 2026-04-08: patched: Fixed versions released
  • 2026-04-08: disclosed: Initial advisory publication

References