CVE-2025-6549: Junos OS: SRX Series: J-Web can be exposed on additional interfaces
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the
Juniper Web Device Manager
(J-Web).
When Juniper Secure connect (JSC) is enabled on specific interfaces, or multiple interfaces are configured for J-Web, the J-Web UI is reachable over more than the intended interfaces. This issue affects Junos OS:
all versions before 21.4R3-S9, 22.2 versions before 22.2R3-S5, 22.4 versions before 22.4R3-S5, 23.2 versions before 23.2R2-S3, 23.4 versions before 23.4R2-S5, 24.2 versions before 24.2R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 21.4R3-S9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.2R3-S5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.4R3-S5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 23.2R2-S3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 23.4R2-S5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.2R2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.4R1 - Configuration
To prevent unintended reachability of the J-Web UI over additional interfaces, disable Juniper Secure connect (JSC) on the specific interfaces where it causes J-Web to be reachable beyond the intended interfaces.
J-Web (Junos OS: SRX Series) JSC (Juniper Secure connect) enabled on specific interfaces = Disable or ensure JSC is not enabled on interfaces where J-Web should not be reachable - Configuration
Ensure J-Web is configured for only the intended interfaces; avoid having multiple interfaces configured in a way that makes the J-Web UI reachable over more interfaces than intended.
J-Web (Junos OS: SRX Series) Interfaces configured for J-Web = Configure J-Web to only the intended interfaces
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6549?
CVE-2025-6549 has a high severity due to its potential for unauthorized access to the Juniper Web Device Manager.
How do I fix CVE-2025-6549?
To fix CVE-2025-6549, users should apply the appropriate Junos OS updates and patches provided by Juniper Networks.
What systems are affected by CVE-2025-6549?
CVE-2025-6549 affects Juniper Networks Junos OS on SRX Series devices that meet specific version criteria.
Can CVE-2025-6549 be exploited remotely?
Yes, CVE-2025-6549 can be exploited by an unauthenticated, network-based attacker targeting the vulnerable web server.
What is the impact of CVE-2025-6549?
The impact of CVE-2025-6549 includes unauthorized access to the Juniper Web Device Manager, potentially allowing attackers to manipulate the device.