CVE-2025-21589: Session Smart Router, Session Smart Conductor, WAN Assurance Router: API Authentication Bypass vulnerability
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device.
This issue affects Session Smart Router:
from 5.6.7 before 5.6.17, from 6.0 before 6.0.8 (affected from 6.0.8),
from 6.1 before 6.1.12-lts, from 6.2 before 6.2.8-lts, from 6.3 before 6.3.3-r2;
This issue affects Session Smart Conductor:
from 5.6.7 before 5.6.17, from 6.0 before 6.0.8 (affected from 6.0.8),
from 6.1 before 6.1.12-lts, from 6.2 before 6.2.8-lts, from 6.3 before 6.3.3-r2;
This issue affects WAN Assurance Managed Routers:
from 5.6.7 before 5.6.17, from 6.0 before 6.0.8 (affected from 6.0.8),
from 6.1 before 6.1.12-lts, from 6.2 before 6.2.8-lts, from 6.3 before 6.3.3-r2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21589?
CVE-2025-21589 is classified as a critical vulnerability due to its potential to allow attackers to bypass authentication on affected Juniper devices.
How do I fix CVE-2025-21589?
To resolve CVE-2025-21589, update affected devices to the latest firmware version provided by Juniper Networks.
Which products are affected by CVE-2025-21589?
CVE-2025-21589 affects Juniper Networks Session Smart Router, Session Smart Conductor, and WAN Assurance Managed Routers.
Can exploiting CVE-2025-21589 lead to a full system compromise?
Yes, exploiting CVE-2025-21589 can allow an attacker to gain administrative access, potentially leading to a full system compromise.
Is there a workaround for CVE-2025-21589 if I cannot update immediately?
Currently, there's no known workaround for CVE-2025-21589, so updating to a secure version is strongly recommended.