CVE-2025-59961: Junos OS and Junos OS Evolved: Unix socket used to control the jdhcpd process is world-writable
An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix socket used to manage the jdhcpd process, resulting in complete control over the resource.
This vulnerability allows any low-privileged user logged into the system to connect to the Unix socket and issue commands to manage the DHCP service, in essence, taking administrative control of the local DHCP server or DHCP relay.
This issue affects: Junos OS: all versions before 21.2R3-S10, all versions of 22.2, from 21.4 before 21.4R3-S12, from 22.4 before 22.4R3-S8, from 23.2 before 23.2R2-S5, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R2-S2, from 24.4 before 24.4R2, from 25.2 before 25.2R1-S1, 25.2R2;
Junos OS Evolved: all versions before 22.4R3-S8-EVO, from 23.2 before 23.2R2-S5-EVO, from 23.4 before 23.4R2-S6-EVO, from 24.2 before 24.2R2-S2-EVO, from 24.4 before 24.4R2-EVO, from 25.2 before 25.2R1-S1-EVO, 25.2R2-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59961?
CVE-2025-59961 has a critical severity rating due to improper permission settings that allow low-privileged users to write to a critical resource.
How do I fix CVE-2025-59961?
To fix CVE-2025-59961, adjust the permissions of the Unix socket used by the jdhcpd process to restrict write access.
Which versions of Junos OS are affected by CVE-2025-59961?
CVE-2025-59961 affects vulnerable versions of Junos OS up to 21.2R3-S10 and 22.2, along with certain versions of Junos OS Evolved up to 22.4.
Can CVE-2025-59961 be exploited remotely?
CVE-2025-59961 cannot be exploited remotely as it requires local access by a low-privileged user.
What impact does CVE-2025-59961 have on system security?
CVE-2025-59961 could allow unauthorized access and potential control over network operations by a low-privileged user, compromising overall system security.