CVE-2025-30650: Junos OS: Privileged local user can gain access to a Linux-based FPC as root
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.
This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: MPC7, MPC8, MPC9, MPC10, MPC11 LC2101, LC2103 LC480, LC4800, LC9600 MX304 (built-in FPC) MX-SPC3 SRX5K-SPC3 EX9200-40XS
FPC3-PTX-U2, FPC3-PTX-U3 FPC3-SFF-PTX LC1101, LC1102, LC1104, LC1105
This issue affects Junos OS:
all versions before 22.4R3-S8, from 23.2 before 23.2R2-S6, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2, from 25.2 before 25.2R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (systems using Linux-based line cards)to a version that resolves this vulnerability.Fixed in 22.4R3-S8 - Upgrade
Upgrade
Juniper Networks Junos OS (systems using Linux-based line cards)to a version that resolves this vulnerability.Fixed in 23.2R2-S6 - Upgrade
Upgrade
Juniper Networks Junos OS (systems using Linux-based line cards)to a version that resolves this vulnerability.Fixed in 23.4R2-S6 - Upgrade
Upgrade
Juniper Networks Junos OS (systems using Linux-based line cards)to a version that resolves this vulnerability.Fixed in 24.2R2-S3 - Upgrade
Upgrade
Juniper Networks Junos OS (systems using Linux-based line cards)to a version that resolves this vulnerability.Fixed in 24.4R2 - Upgrade
Upgrade
Juniper Networks Junos OS (systems using Linux-based line cards)to a version that resolves this vulnerability.Fixed in 25.2R2 - Upgrade
Upgrade
Juniper Networks Junos OS (systems using Linux-based line cards)to a version that resolves this vulnerability.Fixed in 25.4R1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30650?
CVE-2025-30650 is considered a critical vulnerability that allows a privileged local attacker to gain root access on Linux-based line cards.
How do I fix CVE-2025-30650?
To mitigate CVE-2025-30650, it is recommended to update to a patched version of Junos OS that addresses this vulnerability.
Who is affected by CVE-2025-30650?
CVE-2025-30650 affects users of Juniper Networks Junos OS versions up to 22.4R3-S8 and several specific versions from 23.2 to 25.2.
What impact does CVE-2025-30650 have on systems?
The impact of CVE-2025-30650 can lead to unauthorized access and control over critical system functions, compromising the integrity and security of the network.
Is there a workaround for CVE-2025-30650?
Currently, the primary recommendation for CVE-2025-30650 is to upgrade to a secure version, as no specific workaround is provided.