Unrated severityNVD Advisory· Published Jul 11, 2025· Updated Sep 24, 2025
Junos OS and Junos OS Evolved: Annotate configuration command can be used to change the configuration
CVE-2025-52989
Description
An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration.
A user with limited configuration and commit permissions, using a specifically crafted annotate configuration command, can change any part of the device configuration.
This issue affects:
Junos OS:
- all versions before 22.2R3-S7,
- 22.4 versions before 22.4R3-S7,
- 23.2 versions before 23.2R2-S4,
- 23.4 versions before 23.4R2-S4,
- 24.2 versions before 24.2R2-S1,
- 24.4 versions before 24.4R1-S2, 24.4R2;
Junos OS Evolved:
- all versions before 22.4R3-S7-EVO,
- 23.2-EVO versions before 23.2R2-S4-EVO,
- 23.4-EVO versions before 23.4R2-S5-EVO,
- 24.2-EVO versions before 24.2R2-S1-EVO
- 24.4-EVO versions before 24.4R2-EVO.
Affected products
3< 22.4R3-S7-EVO, 23.2-EVO < 23.2R2-S4-EVO, 23.4-EVO < 23.4R2-S5-EVO, 24.2-EVO < 24.2R2-S1-EVO, 24.4-EVO < 24.4R2-EVO+ 1 more
- (no CPE)range: < 22.4R3-S7-EVO, 23.2-EVO < 23.2R2-S4-EVO, 23.4-EVO < 23.4R2-S5-EVO, 24.2-EVO < 24.2R2-S1-EVO, 24.4-EVO < 24.4R2-EVO
- (no CPE)range: 0
- Range: < 22.2R3-S7, 22.4 < 22.4R3-S7, 23.2 < 23.2R2-S4, 23.4 < 23.4R2-S4, 24.2 < 24.2R2-S1, 24.4 < 24.4R1-S2, 24.4 < 24.4R2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- supportportal.juniper.net/JSA100096mitrevendor-advisory
News mentions
0No linked articles in our index yet.