Article Details
Scrape Timestamp (UTC): 2025-02-18 12:27:01.746
Source: https://thehackernews.com/2025/02/juniper-session-smart-routers.html
Original Article Text
Click to Toggle View
Juniper Session Smart Routers Vulnerability Could Let Attackers Bypass Authentication. Juniper Networks has released security updates to address a critical security flaw impacting Session Smart Router, Session Smart Conductor, and WAN Assurance Router products that could be exploited to hijack control of susceptible devices. Tracked as CVE-2025-21589, the vulnerability carries a CVSS v3.1 score of 9.8 and a CVS v4 score of 9.3. "An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allow a network-based attacker to bypass authentication and take administrative control of the device," the company said in an advisory. The vulnerability impacts the following products and versions - Juniper Networks said the vulnerability was discovered during internal product security testing and research, and that it's not aware of any malicious exploitation. The flaw has been addressed in Session Smart Router versions SSR-5.6.17, SSR-6.1.12-lts, SSR-6.2.8-lts, SSR-6.3.3-r2, and later. "This vulnerability has been patched automatically on devices that operate with WAN Assurance (where configuration is also managed) connected to the Mist Cloud," the company added. "As practical, the routers should still be upgraded to a version containing the fix."
Daily Brief Summary
Juniper Networks identified a critical security flaw in their Session Smart Routers, Session Smart Conductor, and WAN Assurance Router products.
The vulnerability, tracked as CVE-2025-21589, has a high severity score of 9.8 on the CVSS v3.1 scale and 9.3 on the CVS v4 scale.
It allows network-based attackers to bypass authentication measures and gain administrative control over the devices.
Affected routers include multiple versions up to SSR-6.3.3-r2; updated versions have patched the vulnerability.
Juniper performed internal security testing and research to discover the flaw before any known malicious exploitation occurred.
Devices connected to the Mist Cloud and using WAN Assurance received automatic patches, though manual updates are recommended for all affected systems.
This vulnerability underscores the critical importance of continuous monitoring and immediate patch management in network devices to protect against potential unauthorized access.