logo

Juniper patches critical auth bypass in Session Smart routers

ID: d04e63ad-5efe-51a2-9f54-8a14d390585f

STIX ID: report--d04e63ad-5efe-51a2-9f54-8a14d390585f

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-02-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Juniper Networks disclosed and patched a critical authentication-bypass vulnerability (CVE-2025-21589) affecting Session Smart Router, Session Smart Conductor, and WAN Assurance Managed Routers that could allow network-based attackers to bypass authentication and take administrative control; Juniper released fixes in specific SSR releases, noted no evidence of active exploitation so far, and advised administrators to upgrade affected systems (Conductor-managed deployments will auto-apply the fix when Conductors are upgraded).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.