GPU VulnDB

Database/Firmware, BMC & network fabric

Junos OS: missing authentication in command processing gives a privileged local user root on line cards

CVE-2025-30650Firmware, BMC & network fabriccurated

Impact

A command-processing path on Junos exposes no authentication check, so a user who already holds privileged CLI access on the routing engine can cross into the Linux-based line cards as root. That is an escalation out of the Junos administrative model into the packet-forwarding hardware itself, where an attacker can persist below the level that a Junos configuration audit or software rollback would inspect. On a datacenter fabric these chassis carry aggregation and edge traffic for many tenants, so a compromised line card sits astride traffic that is not attributable to any single tenant. The record describes local privileged access as the precondition, not remote reachability.

Who can reach it

A local attacker who already holds high-privilege access on the Junos device (AV:L, PR:H). No unauthenticated or network-side path is described in the advisory.

What to do

Upgrade Junos OS to 22.4R3-S8, 23.2R2-S6, 23.4R2-S6, 24.2R2-S3, 24.4R2, 25.2R2 or later, per the vendor bulletin. A Junos upgrade takes the chassis out of service, so schedule a maintenance window and drain traffic to the redundant path first; only chassis running the listed Linux-based line cards are affected. In the interim, tighten who holds privileged Junos accounts and review authentication and command logging on these devices, since the precondition is administrative access.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.