PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-30650 Juniper Networks CVE debrief

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards, including MPC7, MPC8, MPC9, MPC10, MPC11, LC2101, LC2103, LC480, LC4800, LC9600, MX304, MX-SPC3, SRX5K-SPC3, EX9200-40XS, FPC3-PTX-U2, FPC3-PTX-U3, FPC3-SFF-PTX, LC1101, LC1102, LC1104, and LC1105. The issue affects Junos OS versions before 22.4R3-S8, from 23.2 before 23.2R2-S6, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2, and from 25.2 before 25.2R2. Users should review and apply patches to prevent exploitation.

Vendor
Juniper Networks
Product
Junos OS
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-25
Advisory published
2026-04-08
Advisory updated
2026-07-25

Who should care

Users of Juniper Networks Junos OS, particularly those with Linux-based line cards, should review and apply patches to prevent exploitation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact on their systems and implement necessary mitigations.

Technical summary

The vulnerability, CVE-2025-30650, is caused by a missing authentication mechanism for critical functions in Junos OS. This allows a local attacker with privileges to access Linux-based line cards as root. Affected line cards include MPC7, MPC8, MPC9, MPC10, MPC11, LC2101, LC2103, LC480, LC4800, LC9600, MX304, MX-SPC3, SRX5K-SPC3, EX9200-40XS, FPC3-PTX-U2, FPC3-PTX-U3, FPC3-SFF-PTX, LC1101, LC1102, LC1104, and LC1105. The issue affects Junos OS versions before 22.4R3-S8, from 23.2 before 23.2R2-S6, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2, and from 25.2 before 25.2R2.

Defensive priority

High

Recommended defensive actions

  • Apply patches for Junos OS versions before 22.4R3-S8, from 23.2 before 23.2R2-S6, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2, and from 25.2 before 25.2R2
  • Inventory and verify the Junos OS version and installed line cards
  • Implement compensating controls, such as monitoring and exception tracking, until patches can be applied
  • Review and validate affected scope and vendor guidance
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-04-08T19:24:00.440Z and was last modified on 2026-07-25T10:10:00.167Z. The NVD entry is currently Awaiting Analysis. This information is based on the NVD entry and the CVE record. The vulnerability affects systems running Junos OS using Linux-based line cards. Evidence is limited to public sources and may not be comprehensive.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T19:24:00.440Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.