CVE-2025-6549 Information
Jul 12, 2025
cve
Description
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker to reach the
Juniper Web Device Manager
(J-Web).
When Juniper Secure connect (JSC) is enabled on specific interfaces or multiple interfaces are configured for J-Web the J-Web UI is reachable over more than the intended interfaces. This issue affects Junos OS:
all versions before 21.4R3-S9
22.2 versions before 22.2R3-S5
22.4 versions before 22.4R3-S5
23.2 versions before 23.2R2-S3
23.4 versions before 23.4R2-S5
24.2 versions before 24.2R2.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Reference
https://supportportal.juniper.net/JSA100098
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.5
Related CNNVD
CNNVD-202507-1676 (Published: 2025-07-11)
Share on: