GPU VulnDB

Database/Firmware, BMC & network fabric

Juniper Junos OS (httpd / J-Web on QFX5120, EX, SRX, MX): Crafted HTTP requests to the web management process drive CPU

CVE-2025-21601Firmware, BMC & network fabriccurated

Impact

Crafted HTTP requests to the web management process drive CPU consumption up until the device stops responding. QFX5120 is a common data-center leaf, and the vulnerability is in the management daemon, so an attacker who reaches the management interface can take the switch's control plane out without credentials.

Who can reach it

Unauthenticated, remote — reachability to the device's web management service. Only exposed if J-Web / HTTP management is enabled, which many operators leave on for convenience.

What to do

Junos upgrade (24.2R2 or later on QFX5120) plus reboot. The far cheaper immediate fix is a config change: disable J-Web entirely (delete system services web-management) and manage the fabric through NETCONF or the CLI. Most data-center operators should have this off regardless.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.