6.8
MEDIUM CVSS 4.0
CVE-2026-57025
Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash
Description

A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.

INFO

Published Date :

July 9, 2026, 10:17 p.m.

Last Modified :

July 16, 2026, 9:16 a.m.

Remotely Exploit :

No
Affected Products

The following products are affected by CVE-2026-57025 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Juniper junos
2 Juniper junos_os_evolved
3 Juniper ex2300
4 Juniper ex2300-c
5 Juniper ex3400
6 Juniper ex4300
7 Juniper ex4400
8 Juniper ex4600
9 Juniper ex4650
10 Juniper ex9204
11 Juniper ex9208
12 Juniper ex9214
13 Juniper mx2010
14 Juniper mx2020
15 Juniper mx240
16 Juniper mx480
17 Juniper mx960
18 Juniper mx10008
19 Juniper mx2008
20 Juniper mx204
21 Juniper qfx5200
22 Juniper qfx5110
23 Juniper qfx10008
24 Juniper qfx10016
25 Juniper qfx5120
26 Juniper qfx5210
27 Juniper qfx5220
28 Juniper qfx5130
29 Juniper qfx5700
30 Juniper ex4100
31 Juniper ex4100-f
32 Juniper mx10004
33 Juniper mx304
34 Juniper qfx5230-64cd
35 Juniper qfx5240
36 Juniper qfx5241
37 Juniper ex4000
38 Juniper ex4100-h
39 Juniper mx301
40 Juniper ex4100-h-12t
41 Juniper qfx5140
42 Juniper qfx5250
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 MEDIUM 8cbe9d5a-a066-4c94-8978-4b15efeae968
CVSS 3.1 MEDIUM [email protected]
CVSS 3.1 MEDIUM MITRE-CVE
CVSS 4.0 MEDIUM 8cbe9d5a-a066-4c94-8978-4b15efeae968
CVSS 4.0 MEDIUM [email protected]
Solution
Update Junos OS or Junos OS Evolved to a fixed version to prevent Denial-of-Service.
  • Update Junos OS to a fixed version.
  • Update Junos OS Evolved to a fixed version.
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-57025.

URL Resource
https://supportportal.juniper.net/JSA110085 Vendor Advisory
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-57025 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-57025 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-57025 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-57025 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by [email protected]

    Jul. 16, 2026

    Action Type Old Value New Value
    Changed Description A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO. A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.
  • Initial Analysis by [email protected]

    Jul. 13, 2026

    Action Type Old Value New Value
    Added CPE Configuration AND OR *cpe:2.3:o:juniper:junos:23.2:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s3:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s3:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s4:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s4:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.2:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s5:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.2:r2-s5:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:23.4:r2-s6:*:*:*:*:*:* *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions up to (excluding) 23.2 *cpe:2.3:o:juniper:junos:23.2:r2-s6:*:*:*:*:*:* OR cpe:2.3:h:juniper:ex4300:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5110:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx10016:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx10008:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5200:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4600:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx240:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx480:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx960:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx2010:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx2020:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex2300:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex2300-c:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex3400:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5120:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5210:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4650:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex9204:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex9208:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex9214:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx204:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx2008:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx10008:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5220:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5130:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4400:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5700:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4100:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4100-f:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx10004:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx304:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4000:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4100-h:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5230-64cd:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5240:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5241:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx301:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4100-h-12t:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5140:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5250:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:juniper:junos_os_evolved:23.2:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.2:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.2:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.2:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.2:r2-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.2:r2-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:24.2:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:24.2:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r1-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.2:r2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.2:r2-s3:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.2:r2-s4:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s3:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s4:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s5:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:24.2:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:24.4:-:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:24.4:r1:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:24.4:r1-s2:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s6:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:*:*:*:*:*:*:*:* versions up to (excluding) 23.2 *cpe:2.3:o:juniper:junos_os_evolved:23.2:r2-s5:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.2:r2-s6:*:*:*:*:*:* *cpe:2.3:o:juniper:junos_os_evolved:23.4:r2-s7:*:*:*:*:*:* OR cpe:2.3:h:juniper:ex4300:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5110:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx10016:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx10008:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5200:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4600:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx240:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx480:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx960:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx2010:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx2020:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex2300:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex2300-c:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex3400:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5120:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5210:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4650:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex9204:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex9208:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex9214:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx204:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx2008:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx10008:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5220:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5130:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4400:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5700:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4100:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4100-f:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx10004:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx304:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4000:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4100-h:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5230-64cd:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5240:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5241:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:mx301:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:ex4100-h-12t:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5140:-:*:*:*:*:*:*:* cpe:2.3:h:juniper:qfx5250:-:*:*:*:*:*:*:*
    Added Reference Type Juniper Networks, Inc.: https://supportportal.juniper.net/JSA110085 Types: Vendor Advisory
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 10, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2026-57025', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-07-10T14:10:45.027060Z'}
  • New CVE Received by [email protected]

    Jul. 09, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'Juniper Networks', 'product': 'Junos OS', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '23.2R2-S7', 'versionType': 'custom'}, {'status': 'affected', 'version': '23.4', 'lessThan': '23.4R2-S7', 'versionType': 'custom'}, {'status': 'affected', 'version': '24.2', 'lessThan': '24.2R2', 'versionType': 'custom'}, {'status': 'affected', 'version': '24.4', 'lessThan': '24.4R1-S2', 'versionType': 'custom'}], 'platforms': ['EX Series', 'QFX Series', 'MX Series'], 'defaultStatus': 'unaffected'}, {'vendor': 'Juniper Networks', 'product': 'Junos OS Evolved', 'versions': [{'status': 'affected', 'version': '0', 'lessThan': '23.2R2-S7-EVO', 'versionType': 'custom'}, {'status': 'affected', 'version': '23.4', 'lessThan': '23.4R2-S8-EVO', 'versionType': 'custom'}, {'status': 'affected', 'version': '24.2', 'lessThan': '24.2R2-EVO', 'versionType': 'custom'}, {'status': 'affected', 'version': '24.4', 'lessThan': '24.4R1-S3-EVO', 'versionType': 'custom'}], 'defaultStatus': 'unaffected'}]
    Added Description A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.
    Added CVSS V4.0 AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:M/U:X
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
    Added CWE CWE-466
    Added Reference https://supportportal.juniper.net/JSA110085
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.