CVE-2025-59957 Details
Description
An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series and QFX5000 Series allows an unauthenticated attacker with physical access to the device to create a backdoor which allows complete control of the system. When a device isn't configured with a root password, an attacker can modify a specific file. It's contents will be added to the Junos configuration of the device without being visible. This allows for the addition of any configuration unknown to the actual operator, which includes users, IP addresses and other configuration which could allow unauthorized access to the device. This exploit is persistent across reboots and even zeroization. The indicator of compromise is a modified /etc/config/<platform>-defaults[-flex].conf file. Review that file for unexpected configuration statements, or compare it to an unmodified version which can be extracted from the original Juniper software image file. For details on the extraction procedure please contact Juniper Technical Assistance Center (JTAC). To restore the device to a trusted initial configuration the system needs to be reinstalled from physical media. This issue affects Junos OS on EX4600 Series and QFX5000 Series: * All versions before 21.4R3, * 22.2 versions before 22.2R3-S3.
A vulnerability allowing origin validation errors has been identified in Juniper Networks Junos OS, specifically on EX4600 Series and QFX5000 Series switches. This vulnerability allows an unauthenticated attacker with physical access to the device to create a backdoor, granting complete control over the system. The issue arises when a device is not configured with a root password, enabling an attacker to modify a specific file. The alterations are then silently integrated into the Junos configuration, without visibility to the operator. This covertly added configuration can include users, IP addresses, and other settings that might facilitate unauthorized access to the device. Notably, this backdoor persists across reboots and even after a zeroization process. The compromised file is located in the /etc/config/ directory, and its unexpected modifications can be compared against an unaltered version from the original Juniper software image. To restore the device to a trusted state, a reinstallation from physical media is required.
To address this vulnerability, the device should be reinstalled from physical media. Instructions for performing a recovery installation using a USB emergency boot device are available in the Juniper Support Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.juniper.net/support/requesting-support/ | [email protected] | Vendor Advisory |
| https://supportportal.juniper.net/JSA103146 | [email protected] | Vendor Advisory |
| https://supportportal.juniper.net/s/article/EX-QFX-Procedure-to-format-install-QFX5K-device-using-a-USB | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | < 21.4 21.4 - 21.4 r1 21.4 r1-s1 21.4 r1-s2 21.4 r2 21.4 r2-s1 21.4 r2-s2 22.2 - 22.2 r1 22.2 r1-s1 22.2 r1-s2 22.2 r2 22.2 r2-s1 22.2 r2-s2 22.2 r3 22.2 r3-s1 22.2 r3-s2 |
CPE
Remediation
| |
| juniper ex4600 | All versions |
CPE
Remediation
| |
| juniper ex4650 | All versions |
CPE
Remediation
| |
| juniper qfx5110 | All versions |
CPE
Remediation
| |
| juniper qfx5120 | All versions |
CPE
Remediation
| |
| juniper qfx5130 | All versions |
CPE
Remediation
| |
| juniper qfx5200 | All versions |
CPE
Remediation
| |
| juniper qfx5210 | All versions |
CPE
Remediation
| |
| juniper qfx5220 | All versions |
CPE
Remediation
| |
| juniper qfx5230-64cd | All versions |
CPE
Remediation
| |
| juniper qfx5240 | All versions |
CPE
Remediation
| |
| juniper qfx5241 | All versions |
CPE
Remediation
| |
| juniper qfx5700 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Oct 9, 2025 | New CVE Received | [email protected] |