• News/
  • https://www.bleepingcomputer.com/news/security/juniper-patches-critical-auth-bypass-in-session-smart-routers/

Juniper patches critical auth bypass in Session Smart routers

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 18, 2025
·
Updated

​Juniper Networks has patched a critical vulnerability that allows attackers to bypass authentication and take over Session Smart Router (SSR) devices. The security flaw (tracked as CVE-2025-21589) was found during internal product security testing, and it also affects Session Smart Conductor and WAN Assurance Managed Routers. "An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allow a network-based attacker to bypass authentication and take administrative control of the device," the American networking infrastructure company said in an out-of-cycle security advisory released last week. According to Juniper's Security Incident Response Team (SIRT), the company has yet to find evidence that the vulnerability has been targeted in attacks. Juniper has fixed the vulnerability in SSR-5.6.17, SSR-6.1.12-lts, SSR-6.2.8-lts, SSR-6.3.3-r2, and subsequent releases. While the company says that some devices connected to the Mist Cloud have already been patched, admins are advised to upgrade all affected systems to one of these patched software versions. "In a Conductor-managed deployment, it is sufficient to upgrade only the Conductor nodes and the fix will be applied automatically to all connected routers. As practical, the routers should still be upgraded to a fixed version however they will not be vulnerable once they connect to an upgraded Conductor," Juniper said. Juniper devices are commonly targeted in attacks du...

Read full article

Affected Software

12 affected components
Juniper Networks Session Smart Router=SSR-5.6.17
Juniper Networks Session Smart Router=SSR-6.1.12-lts
Juniper Networks Session Smart Router=SSR-6.2.8-lts
Juniper Networks Session Smart Router=SSR-6.3.3-r2
Juniper Networks Session Smart Conductor
Juniper Networks WAN Assurance Managed Routers
Juniper Networks Session Smart Router=SSR-5.6.17
Juniper Networks Session Smart Router=SSR-6.1.12-lts
Juniper Networks Session Smart Router=SSR-6.2.8-lts
Juniper Networks Session Smart Router=SSR-6.3.3-r2
Juniper Networks Session Smart Conductor
Juniper Networks WAN Assurance Managed Routers
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerability has been patched by Juniper Networks?

Juniper Networks has patched a critical authentication bypass vulnerability in their Session Smart routers.

2

What is the identification number for the security flaw?

The vulnerability is tracked as CVE-2025-21589.

3

Which products are affected by this vulnerability?

The affected products include Juniper Networks Session Smart Routers with versions SSR-5.6.17, SSR-6.1.12-lts, SSR-6.2.8-lts, and SSR-6.3.3-r2.

4

What can attackers do by exploiting this vulnerability?

Exploiting this vulnerability allows attackers to bypass authentication and potentially take over the affected devices.

5

How did the vulnerability come to Juniper's attention?

The security flaw was discovered during internal product security assessments at Juniper Networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203