CVE-2025-6549: CWE-863 Incorrect Authorization in Juniper Networks Junos OS
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the Juniper Web Device Manager (J-Web). When Juniper Secure connect (JSC) is enabled on specific interfaces, or multiple interfaces are configured for J-Web, the J-Web UI is reachable over more than the intended interfaces. This issue affects Junos OS: * all versions before 21.4R3-S9, * 22.2 versions before 22.2R3-S5, * 22.4 versions before 22.4R3-S5, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S5, * 24.2 versions before 24.2R2.
CVE-2025-6549: CWE-863 Incorrect Authorization in Juniper Networks Junos OS
Description
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the Juniper Web Device Manager (J-Web). When Juniper Secure connect (JSC) is enabled on specific interfaces, or multiple interfaces are configured for J-Web, the J-Web UI is reachable over more than the intended interfaces. This issue affects Junos OS: * all versions before 21.4R3-S9, * 22.2 versions before 22.2R3-S5, * 22.4 versions before 22.4R3-S5, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S5, * 24.2 versions before 24.2R2.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- juniper
- Date Reserved
- 2025-06-23T19:28:49.259Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68712e3ba83201eaacaf5d27
Added to database: 7/11/2025, 3:31:07 PM
Last updated: 7/11/2025, 3:31:07 PM
Views: 1
Related Threats
CVE-2025-52989: CWE-140 Improper Neutralization of Delimiters in Juniper Networks Junos OS
MediumCVE-2025-52988: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Juniper Networks Junos OS
MediumCVE-2025-52986: CWE-401 Missing Release of Memory after Effective Lifetime in Juniper Networks Junos OS
MediumCVE-2025-52985: CWE-480 Use of Incorrect Operator in Juniper Networks Junos OS Evolved
MediumCVE-2025-52984: CWE-476 NULL Pointer Dereference in Juniper Networks Junos OS
MediumActions
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.