logo

Juniper patches bug that let Chinese cyberspies backdoor routers

ID: 763c9f7c-4993-584e-8369-5e88570742e0

STIX ID: report--763c9f7c-4993-584e-8369-5e88570742e0

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-03-13

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Juniper released emergency patches for CVE-2025-21590 — an improper isolation flaw in Junos OS that allows local, privileged attackers to execute arbitrary code — after Mandiant reported China-linked UNC3886 had exploited the bug since 2024 to deploy multiple backdoors on end-of-life Juniper routers; CISA added the CVE to its catalog and urged federal agencies to remediate immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.