• News/
  • https://www.bleepingcomputer.com/news/security/juniper-patches-bug-that-let-chinese-cyberspies-backdoor-routers-since-mid-2024/

Juniper patches bug that let Chinese cyberspies backdoor routers

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 13, 2025
·
Updated

​Juniper Networks has released emergency security updates to patch a Junos OS vulnerability exploited by Chinese hackers to backdoor routers for stealthy access. This medium severity flaw (CVE-2025-21590) was reported by Amazon security engineer Matteo Memelli and is caused by an improper isolation or compartmentalization weakness. Successful exploitation lets local attackers with high privileges execute arbitrary code on vulnerable routers to compromise the devices' integrity. "At least one instance of malicious exploitation (not at Amazon) has been reported to the Juniper SIRT. Customers are encouraged to upgrade to a fixed release as soon as it's available and in the meantime take steps to mitigate this vulnerability," Juniper warned in an out-of-cycle security advisory issued on Wednesday, "While the complete list of resolved platforms is under investigation, it is strongly recommended to mitigate the risk of exploitation by restricting shell access to trusted users only." The vulnerability impacts NFX-Series, Virtual SRX, SRX-Series Branch, SRX-Series HE, EX-Series, QFX-Series, ACX, and MX-Series devices and was resolved in 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases. CISA also added CVE-2025-21590 to its catalog of actively exploited vulnerabilities on Thursday, ordering Federal Civilian Executive Branch (FCEB) agencies to secure vulnerable Juniper devices by April 3rd as mandated by Binding Operational Directive ...

Read full article

Affected Software

10 affected components
Juniper Networks Junos OS
Juniper Networks NFX-Series
Juniper Networks Virtual SRX
Juniper Networks SRX-Series Branch
Juniper Networks SRX-Series HE
Juniper Networks EX-Series
Juniper Networks QFX-Series
Juniper Networks ACX
Juniper Networks MX-Series
Juniper Networks Junos OS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main issue addressed in this article?

The article discusses a vulnerability in Junos OS that allowed Chinese cyberspies to backdoor routers.

2

Which specific vulnerabilities are detailed in this security update?

The article highlights the medium severity flaw identified as CVE-2025-21590.

3

What products are impacted by this Juniper security vulnerability?

The affected products include various Juniper Networks devices such as Junos OS, NFX-Series, Virtual SRX, and more.

4

What actions has Juniper Networks taken in response to this security threat?

Juniper Networks has released emergency security updates to patch the identified vulnerability.

5

What type of access did the vulnerability provide to the attackers?

The vulnerability allowed attackers to gain stealthy access to the routers by installing a backdoor.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203