CVE-2025-52984: Junos OS and Junos OS Evolved: When a static route points to a reject next-hop and a gNMI query for this route is processed, RPD crashes
A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause impact to the availability of the device.
When static route points to a reject next hop and a gNMI query is processed for that static route, rpd crashes and restarts.
This issue affects:
Junos OS: all versions before 21.2R3-S9, 21.4 versions before 21.4R3-S10, 22.2 versions before 22.2R3-S6, 22.4 versions before 22.4R3-S6, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R1-S2, 24.2R2;
Junos OS Evolved:
all versions before 22.4R3-S7-EVO, 23.2-EVO
versions before 23.2R2-S3-EVO, 23.4-EVO versions before 23.4R2-S4-EVO, 24.2-EVO versions before 24.2R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52984?
CVE-2025-52984 is considered a high severity vulnerability due to its potential impact on device availability.
How do I fix CVE-2025-52984?
To fix CVE-2025-52984, update your Junos OS or Junos OS Evolved to a version that addresses the vulnerability.
What devices are affected by CVE-2025-52984?
CVE-2025-52984 affects various versions of Juniper Networks' Junos OS and Junos OS Evolved.
Can CVE-2025-52984 be exploited remotely?
Yes, CVE-2025-52984 can be exploited by unauthenticated, network-based attackers.
What type of vulnerability is CVE-2025-52984?
CVE-2025-52984 is a NULL Pointer Dereference vulnerability.