CVE-2025-52952: Junos OS: MX Series with MPC-BUILTIN, MPC 1 through MPC 9: Receipt and processing of a malformed packet causes one or more FPCs to crash

Published Jul 11, 2025
·
Updated

An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line cards allows an unauthenticated adjacent attacker to send a malformed packet to the device, leading to an FPC crash and restart, resulting in a Denial of Service (DoS).

Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.

This issue affects Juniper Networks: Junos OS: All versions before 22.2R3-S1, from 22.4 before 22.4R2.

This feature is not enabled by default.

Affected Software

47 affected components
Juniper Networks Junos OS<22.2R3-S1, >=22.4, <undefined
All of the following
Any of the following
Juniper Junos<22.2
Juniper Junos=22.2
Juniper Junos=22.2-r1
Juniper Junos=22.2-r1-s1
Juniper Junos=22.2-r1-s2
Juniper Junos=22.2-r2
Juniper Junos=22.2-r2-s1
Juniper Junos=22.2-r2-s2
Juniper Junos=22.2-r3
Juniper Junos=22.4
Juniper Junos=22.4-r1
Juniper Junos=22.4-r1-s1
Juniper Junos=22.4-r1-s2
Any of the following
Juniper 2x100ge \+ 4x10ge Mpc5e
Juniper 2x100ge \+ 4x10ge Mpc5eq
Juniper 2x100ge \+ 8x10ge Mpc4e
Juniper 32x10ge Mpc4e
Juniper 6x40ge \+ 24x10ge Mpc5e
Juniper 6x40ge \+ 24x10ge Mpc5eq
Juniper MPC1
Juniper Mpc1 Q
Juniper Mpc1e
Juniper Mpc1e Q
Juniper Mpc2
Juniper Mpc2 Eq
Juniper Mpc2 Q
Juniper Mpc2e
Juniper Mpc2e Eq
Juniper Mpc2e Ng
Juniper Mpc2e Ng Q
Juniper Mpc2e P
Juniper Mpc2e Q
Juniper Mpc3e
Juniper Mpc3e-3d-ng
Juniper Mpc3e-3d-ng-q
Juniper Mpc6e
Juniper Mpc7e-10g
Juniper Mpc7e-mrate
Juniper Mpc8e
Juniper Mpc9e
Juniper MX2008
Juniper MX2010
Juniper MX2020
Juniper MX240
Juniper MX480
Juniper MX960

Remediation

Information

The following software releases have been updated to resolve these issues: Junos OS: 22.2R3-S1, 22.4R2, 23.2R1, and all subsequent releases.

Event History

Jul 11, 2025
CVE Published
via MITRE·03:04 PM
Data Sourced
via MITRE·03:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-52952?

The severity of CVE-2025-52952 is considered critical due to the potential for an unauthenticated adjacent attacker to exploit the vulnerability.

2

How do I fix CVE-2025-52952?

To fix CVE-2025-52952, it is recommended to upgrade Junos OS to a version that includes the security patch addressing this vulnerability.

3

What devices are affected by CVE-2025-52952?

CVE-2025-52952 affects Juniper Networks Junos OS on MX Series with MPC1 through MPC9 line cards.

4

What kind of attack is possible with CVE-2025-52952?

CVE-2025-52952 allows an unauthenticated adjacent attacker to send a malformed packet, potentially leading to a system crash.

5

When was CVE-2025-52952 published?

CVE-2025-52952 was published in 2025 and is relevant to vulnerabilities found in Juniper Networks software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203