logo

Juniper Networks fixed a critical flaw in Session Smart Routers

ID: 240c5cf4-d28b-547c-873e-faba61f70ca8

STIX ID: report--240c5cf4-d28b-547c-873e-faba61f70ca8

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2025-02-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Juniper Networks patched a critical authentication bypass (CVE-2025-21589, CVSS 9.8) in Session Smart Router, Session Smart Conductor and WAN Assurance affecting multiple version ranges; fixed releases (SSR-5.6.17, SSR-6.1.12-lts, SSR-6.2.8-lts, SSR-6.3.3-r2 and later) were issued and WAN Assurance with Mist Cloud received automatic updates. The flaw can allow a network-based attacker to bypass authentication and gain administrative control; Juniper states there are no known in-the-wild exploits and recommends upgrading to the fixed versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.