Juniper Networks has released emergency security updates to patch a Junos OS vulnerability exploited by Chinese hackers to backdoor routers for stealthy access. This medium severity flaw (CVE-2025-21590) was reported by Amazon security engineer Matteo Memelli and is caused by an improper isolation or compartmentalization weakness. Successful exploitation lets local attackers with high privileges execute arbitrary code on vulnerable routers to compromise the devices' integrity. "At least one instance of malicious exploitation (not at Amazon) has been reported to the Juniper SIRT. Customers are encouraged to upgrade to a fixed release as soon as it's available and in the meantime take steps to mitigate this vulnerability," Juniper warned in an out-of-cycle security advisory issued on Wednesday, "While the complete list of resolved platforms is under investigation, it is strongly recommended to mitigate the risk of exploitation by restricting shell access to trusted users only." The vulnerability impacts NFX-Series, Virtual SRX, SRX-Series Branch, SRX-Series HE, EX-Series, QFX-Series, ACX, and MX-Series devices and was resolved in 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 24.2R1-S2, 24.2R2, 24.4R1, and all subsequent releases. CISA also added CVE-2025-21590 to its catalog of actively exploited vulnerabilities on Thursday, ordering Federal Civilian Executive Branch (FCEB) agencies to secure vulnerable Juniper devices by April 3rd as mandated by Binding Operational Directive ...
Juniper patches bug that let Chinese cyberspies backdoor routers
BleepingComputer
·Sergiu Gatlan
·Published Mar 13, 2025
·Updated
Affected Software
10 affected components
Juniper Networks Junos OS
Juniper Networks NFX-Series
Juniper Networks Virtual SRX
Juniper Networks SRX-Series Branch
Juniper Networks SRX-Series HE
Juniper Networks EX-Series
Juniper Networks QFX-Series
Juniper Networks ACX
Juniper Networks MX-Series
Juniper Networks Junos OS
Frequently Asked Questions
1
What is the main issue addressed in this article?
The article discusses a vulnerability in Junos OS that allowed Chinese cyberspies to backdoor routers.
2
Which specific vulnerabilities are detailed in this security update?
The article highlights the medium severity flaw identified as CVE-2025-21590.
3
What products are impacted by this Juniper security vulnerability?
The affected products include various Juniper Networks devices such as Junos OS, NFX-Series, Virtual SRX, and more.
4
What actions has Juniper Networks taken in response to this security threat?
Juniper Networks has released emergency security updates to patch the identified vulnerability.
5
What type of access did the vulnerability provide to the attackers?
The vulnerability allowed attackers to gain stealthy access to the routers by installing a backdoor.