8.4
HIGH CVSS 4.0
CVE-2025-30650
Junos OS: Privileged local user can gain access to a Linux-based FPC as root
Description

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: * MPC7, MPC8, MPC9, MPC10, MPC11 * LC2101, LC2103 * LC480, LC4800, LC9600 * MX304 (built-in FPC) * MX-SPC3 * SRX5K-SPC3 * EX9200-40XS * FPC3-PTX-U2, FPC3-PTX-U3 * FPC3-SFF-PTX * LC1101, LC1102, LC1104, LC1105 This issue affects Junos OS:  * all versions before 22.4R3-S8,  * from 23.2 before 23.2R2-S6,  * from 23.4 before 23.4R2-S6,  * from 24.2 before 24.2R2-S3,  * from 24.4 before 24.4R2, * from 25.2 before 25.2R2.

INFO

Published Date :

April 8, 2026, 7:24 p.m.

Last Modified :

Aug. 26, 2026, 4:52 p.m.

Remotely Exploit :

No
Affected Products

The following products are affected by CVE-2025-30650 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Juniper junos
2 Juniper ex9200
3 Juniper mx304
4 Juniper lc9600
5 Juniper mpc11
6 Juniper mx-spc3
7 Juniper mpc10
8 Juniper srx5k-spc3
9 Juniper mpc7e-10g
10 Juniper mpc8e
11 Juniper mpc9e
12 Juniper lc4800
13 Juniper lc2101
14 Juniper lc480
15 Juniper fpc3-ptx-u2
16 Juniper fpc3-ptx-u3
17 Juniper fpc3-sff-ptx
18 Juniper lc1101
19 Juniper lc1102
20 Juniper lc1104
21 Juniper lc1105
22 Juniper lc2103
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 MEDIUM 8cbe9d5a-a066-4c94-8978-4b15efeae968
CVSS 3.1 MEDIUM [email protected]
CVSS 4.0 HIGH 8cbe9d5a-a066-4c94-8978-4b15efeae968
CVSS 4.0 HIGH [email protected]
Solution
Address missing authentication flaws to prevent unauthorized root access on line cards.
  • Apply security updates for Junos OS to affected line cards.
  • Consult Juniper security advisories for specific version guidance.
  • Implement robust authentication controls for critical functions.
  • Restrict local access to line card command processing.
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2025-30650.

URL Resource
https://github.com/orangecertcc/security-research/security/advisories/GHSA-fwhc-gh5m-v8fq Third Party Advisory
https://kb.juniper.net/JSA107863 Vendor Advisory
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-30650 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-30650 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2025-30650 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Aug. 26, 2026

    Action Type Old Value New Value
    Added CPE Configuration AND OR *cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r3:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r2-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r2-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r3-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r3-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r3-s4:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r3-s5:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s3:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:r2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r3-s6:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:22.4:r3-s7:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s3:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s4:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s4:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:r2-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s5:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:r2-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:25.2:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:25.2:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:25.2:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:25.2:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s5:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:*:-:*:*:*:*:*:* versions up to (including) 22.4 OR cpe:2.3:h:juniper:ex9200:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx304:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:lc9600:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mpc10:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mpc11:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx-spc3:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:srx5k-spc3:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:lc2101:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:lc480:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mpc7e-10g:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mpc8e:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mpc9e:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:lc4800:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:lc2103:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:fpc3-sff-ptx:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:lc1101:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:lc1102:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:lc1104:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:lc1105:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:fpc3-ptx-u2:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:fpc3-ptx-u3:-:*:*:*:*:*:*:*
    Added Reference Type Juniper Networks, Inc.: https://github.com/orangecertcc/security-research/security/advisories/GHSA-fwhc-gh5m-v8fq Types: Third Party Advisory
    Added Reference Type Juniper Networks, Inc.: https://kb.juniper.net/JSA107863 Types: Vendor Advisory
  • CVE Translated by [email protected]

    Jul. 25, 2026

    Action Type Old Value New Value
    Added Translation Title: Junos OS de Juniper Networks, Description: Una vulnerabilidad de autenticación faltante para función crítica en el procesamiento de comandos de Juniper Networks Junos OS permite a un atacante local privilegiado obtener acceso a las tarjetas de línea que ejecutan Junos OS Evolved como root. Este problema afecta a los sistemas que ejecutan Junos OS que utilizan tarjetas de línea basadas en Linux. Las tarjetas de línea afectadas incluyen: * MPC7, MPC8, MPC9, MPC10, MPC11 * LC2101, LC2103 * LC480, LC4800, LC9600 * MX304 (FPC integrado) * MX-SPC3 * SRX5K-SPC3 * EX9200-40XS * FPC3-PTX-U2, FPC3-PTX-U3 * FPC3-SFF-PTX * LC1101, LC1102, LC1104, LC1105 Este problema afecta a Junos OS: * todas las versiones anteriores a 22.4R3-S8, * desde 23.2 antes de 23.2R2-S6, * desde 23.4 antes de 23.4R2-S6, * desde 24.2 antes de 24.2R2-S3, * desde 24.4 antes de 24.4R2, * desde 25.2 antes de 25.2R2.
  • CVE Modified by [email protected]

    Jun. 17, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'Juniper Networks', 'product': 'Junos OS', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '22.4R3-S8', 'versionType': 'semver'}, {'status': 'affected', 'version': '23.2', 'lessThan': '23.2R2-S6', 'versionType': 'semver'}, {'status': 'affected', 'version': '23.4', 'lessThan': '23.4R2-S6', 'versionType': 'semver'}, {'status': 'affected', 'version': '24.2', 'lessThan': '24.2R2-S3', 'versionType': 'semver'}, {'status': 'affected', 'version': '24.4', 'lessThan': '24.4R2', 'versionType': 'semver'}, {'status': 'affected', 'version': '25.2', 'lessThan': '25.2R2', 'versionType': 'semver'}], 'defaultStatus': 'unaffected'}]
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jun. 17, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2025-30650', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-04-08T20:06:27.813930Z'}
  • CVE Modified by [email protected]

    Apr. 13, 2026

    Action Type Old Value New Value
    Changed Description A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to line cards running Junos OS Evolved as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: * MPC7, MPC8, MPC9, MPC10, MPC11 * LC2101, LC2103 * LC480, LC4800, LC9600 * MX304 (built-in FPC) * MX-SPC3 * SRX5K-SPC3 * EX9200-40XS * FPC3-PTX-U2, FPC3-PTX-U3 * FPC3-SFF-PTX * LC1101, LC1102, LC1104, LC1105 This issue affects Junos OS:  * all versions before 22.4R3-S8,  * from 23.2 before 23.2R2-S6,  * from 23.4 before 23.4R2-S6,  * from 24.2 before 24.2R2-S3,  * from 24.4 before 24.4R2, * from 25.2 before 25.2R2. A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: * MPC7, MPC8, MPC9, MPC10, MPC11 * LC2101, LC2103 * LC480, LC4800, LC9600 * MX304 (built-in FPC) * MX-SPC3 * SRX5K-SPC3 * EX9200-40XS * FPC3-PTX-U2, FPC3-PTX-U3 * FPC3-SFF-PTX * LC1101, LC1102, LC1104, LC1105 This issue affects Junos OS:  * all versions before 22.4R3-S8,  * from 23.2 before 23.2R2-S6,  * from 23.4 before 23.4R2-S6,  * from 24.2 before 24.2R2-S3,  * from 24.4 before 24.4R2, * from 25.2 before 25.2R2.
  • CVE Modified by [email protected]

    Apr. 09, 2026

    Action Type Old Value New Value
    Removed Reference https://supportportal.juniper.net/JSA107863
  • New CVE Received by [email protected]

    Apr. 08, 2026

    Action Type Old Value New Value
    Added Description A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to line cards running Junos OS Evolved as root. This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include: * MPC7, MPC8, MPC9, MPC10, MPC11 * LC2101, LC2103 * LC480, LC4800, LC9600 * MX304 (built-in FPC) * MX-SPC3 * SRX5K-SPC3 * EX9200-40XS * FPC3-PTX-U2, FPC3-PTX-U3 * FPC3-SFF-PTX * LC1101, LC1102, LC1104, LC1105 This issue affects Junos OS:  * all versions before 22.4R3-S8,  * from 23.2 before 23.2R2-S6,  * from 23.4 before 23.4R2-S6,  * from 24.2 before 24.2R2-S3,  * from 24.4 before 24.4R2, * from 25.2 before 25.2R2.
    Added CVSS V4.0 AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:C/RE:M/U:Amber
    Added CVSS V3.1 AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-306
    Added Reference https://github.com/orangecertcc/security-research/security/advisories/GHSA-fwhc-gh5m-v8fq
    Added Reference https://kb.juniper.net/JSA107863
    Added Reference https://supportportal.juniper.net/JSA107863
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.