CVE-2025-52989: Junos OS and Junos OS Evolved: Annotate configuration command can be used to change the configuration

Published Jul 11, 2025
·
Updated

An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration.

A user with limited configuration and commit permissions, using a specifically crafted annotate configuration command, can change any part of the device configuration.

This issue affects:

Junos OS:

all versions before 22.2R3-S7, 22.4 versions before 22.4R3-S7, 23.2 versions before 23.2R2-S4, 23.4 versions before 23.4R2-S4, 24.2 versions before 24.2R2-S1, 24.4 versions before 24.4R1-S2, 24.4R2;

Junos OS Evolved:

all versions before 22.4R3-S7-EVO, 23.2-EVO versions before 23.2R2-S4-EVO, 23.4-EVO versions before 23.4R2-S5-EVO,  24.2-EVO versions before 24.2R2-S1-EVO

24.4-EVO versions before 24.4R2-EVO.

Affected Software

95 affected components
Juniper Networks Junos OS<22.2R3-S7, <22.4R3-S7, <23.2R2-S4, <23.4R2-S4, <24.2R2-S1, <24.4R1-S2, <24.4R2
Juniper Networks Junos OS Evolved<22.4R3-S7-EVO, <23.2R2-S4-EVO, <23.4R2-S5-EVO, <24.2R2-S1-EVO, <24.4R2-EVO
Juniper Junos<22.2
Juniper Junos=22.2
Juniper Junos=22.2-r1
Juniper Junos=22.2-r1-s1
Juniper Junos=22.2-r1-s2
Juniper Junos=22.2-r2
Juniper Junos=22.2-r2-s1
Juniper Junos=22.2-r2-s2
Juniper Junos=22.2-r3
Juniper Junos=22.2-r3-s1
Juniper Junos=22.2-r3-s2
Juniper Junos=22.2-r3-s3
Juniper Junos=22.2-r3-s4
Juniper Junos=22.2-r3-s5
Juniper Junos=22.2-r3-s6
Juniper Junos=22.4
Juniper Junos=22.4-r1
Juniper Junos=22.4-r1-s1
Juniper Junos=22.4-r1-s2
Juniper Junos=22.4-r2
Juniper Junos=22.4-r2-s1
Juniper Junos=22.4-r2-s2
Juniper Junos=22.4-r3
Juniper Junos=22.4-r3-s1
Juniper Junos=22.4-r3-s2
Juniper Junos=22.4-r3-s3
Juniper Junos=22.4-r3-s4
Juniper Junos=22.4-r3-s5
Juniper Junos=22.4-r3-s6
Juniper Junos=23.2
Juniper Junos=23.2-r1
Juniper Junos=23.2-r1-s1
Juniper Junos=23.2-r1-s2
Juniper Junos=23.2-r2
Juniper Junos=23.2-r2-s1
Juniper Junos=23.2-r2-s2
Juniper Junos=23.2-r2-s3
Juniper Junos=23.4
Juniper Junos=23.4-r1
Juniper Junos=23.4-r1-s1
Juniper Junos=23.4-r1-s2
Juniper Junos=23.4-r2
Juniper Junos=23.4-r2-s1
Juniper Junos=23.4-r2-s2
Juniper Junos=23.4-r2-s3
Juniper Junos=24.2
Juniper Junos=24.2-r1
Juniper Junos=24.2-r1-s1
Juniper Junos=24.2-r1-s2
Juniper Junos=24.2-r2
Juniper Junos=24.4
Juniper Junos=24.4-r1
Juniper Junos=24.4-r2
Juniper Junos OS Evolved<22.4
Juniper Junos OS Evolved=22.4
Juniper Junos OS Evolved=22.4-r1
Juniper Junos OS Evolved=22.4-r1-s1
Juniper Junos OS Evolved=22.4-r1-s2
Juniper Junos OS Evolved=22.4-r2
Juniper Junos OS Evolved=22.4-r2-s1
Juniper Junos OS Evolved=22.4-r2-s2
Juniper Junos OS Evolved=22.4-r3
Juniper Junos OS Evolved=22.4-r3-s1
Juniper Junos OS Evolved=22.4-r3-s2
Juniper Junos OS Evolved=22.4-r3-s3
Juniper Junos OS Evolved=22.4-r3-s4
Juniper Junos OS Evolved=22.4-r3-s5
Juniper Junos OS Evolved=22.4-r3-s6
Juniper Junos OS Evolved=23.2
Juniper Junos OS Evolved=23.2-r1
Juniper Junos OS Evolved=23.2-r1-s1
Juniper Junos OS Evolved=23.2-r1-s2
Juniper Junos OS Evolved=23.2-r2
Juniper Junos OS Evolved=23.2-r2-s1
Juniper Junos OS Evolved=23.2-r2-s2
Juniper Junos OS Evolved=23.2-r2-s3
Juniper Junos OS Evolved=23.4
Juniper Junos OS Evolved=23.4-r1
Juniper Junos OS Evolved=23.4-r1-s1
Juniper Junos OS Evolved=23.4-r1-s2
Juniper Junos OS Evolved=23.4-r2
Juniper Junos OS Evolved=23.4-r2-s1
Juniper Junos OS Evolved=23.4-r2-s2
Juniper Junos OS Evolved=23.4-r2-s3
Juniper Junos OS Evolved=23.4-r2-s4
Juniper Junos OS Evolved=24.2
Juniper Junos OS Evolved=24.2-r1
Juniper Junos OS Evolved=24.2-r1-s2
Juniper Junos OS Evolved=24.2-r2
Juniper Junos OS Evolved=24.4
Juniper Junos OS Evolved=24.4-r1
Juniper Junos OS Evolved=24.4-r1-s2
Juniper Junos OS Evolved=24.4-r1-s3

Remediation

Information

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R2-EVO, 25.2R1-EVO; Junos OS: 22.2R3-S7, 22.4R3-S7, 23.2R2-S4, 23.4R2-S4, 24.2R2-S1, 24.4R1-S2, 24.4R2, 25.2R1, and all subsequent releases.

Event History

Jul 11, 2025
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-52989?

CVE-2025-52989 is classified as a high severity vulnerability due to its potential for unauthorized modification of system configurations.

2

How do I fix CVE-2025-52989?

To remediate CVE-2025-52989, upgrade your Junos OS or Junos OS Evolved to the latest non-vulnerable versions as recommended by Juniper Networks.

3

Who is affected by CVE-2025-52989?

CVE-2025-52989 affects users of Juniper Networks Junos OS and Junos OS Evolved versions up to specific vulnerable releases.

4

What type of attack does CVE-2025-52989 enable?

CVE-2025-52989 allows a local, authenticated attacker with high privileges to improperly modify system configuration.

5

What software is vulnerable to CVE-2025-52989?

CVE-2025-52989 affects multiple versions of Juniper Networks Junos OS and Junos OS Evolved, including several prior to their latest releases.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203