CVE-2025-30650

MEDIUM

Junos OS: Privileged local user can gain access to a Linux-based FPC as root

Title source: cna
STIX 2.1

Description

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: * MPC7, MPC8, MPC9, MPC10, MPC11 * LC2101, LC2103 * LC480, LC4800, LC9600 * MX304 (built-in FPC) * MX-SPC3 * SRX5K-SPC3 * EX9200-40XS * FPC3-PTX-U2, FPC3-PTX-U3 * FPC3-SFF-PTX * LC1101, LC1102, LC1104, LC1105 This issue affects Junos OS:  * all versions before 22.4R3-S8,  * from 23.2 before 23.2R2-S6,  * from 23.4 before 23.4R2-S6,  * from 24.2 before 24.2R2-S3,  * from 24.4 before 24.4R2, * from 25.2 before 25.2R2.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
https://kb.juniper.net/JSA107863

Scores

CVSS v3 6.7
EPSS 0.0014
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (7)
Juniper Networks/Junos OS < 22.4R3-S8
Juniper Networks/Junos OS 23.2 - 23.2R2-S6
Juniper Networks/Junos OS 23.4 - 23.4R2-S6
Juniper Networks/Junos OS 24.2 - 24.2R2-S3
Juniper Networks/Junos OS 24.4 - 24.4R2
Juniper Networks/Junos OS 25.2 - 25.2R2
Juniper Networks/Junos OS all versions - 22.4R3-S8
Published Apr 08, 2026
Tracked Since Apr 09, 2026