Juniper Networks began 2025 with security updates that address dozens of vulnerabilities in the Junos OS, including several high-severity bugs.
See also: Juniper Networks patches serious “auth bypass” vulnerability

Patches were released last week to resolve a high-severity out-of-bounds read flaw in the routing protocol daemon (RPD) of Junos OS and Junos OS Evolved, which could lead to a denial of service (DoS) when processing a malformed BGP packet.
Known as CVE-2025-21598, the issue affects systems that have packet capture monitoring options enabled and "can propagate and multiply through multiple ASes until it reaches vulnerable devices," Juniper says.
As a workaround, users should disable packet sniffing options. To detect potential violations, they should look for malformed update messages on neighboring, unaffected AS devices.
The security updates also fix CVE-2025-21599, a high-severity vulnerability in Juniper Tunnel Driver (JTD) , which could be exploited over the network, without authentication, to cause a DoS.
See also: New botnet targets industrial routers with zero-day exploits
The company also released fixes for two high-severity vulnerabilities inOpenSSH used in Junos OS and Junos OS Evolved, tracked as CVE-2024-6387, which is known as regreSSHion , and CVE-2024-39894.

Last week, Juniper also announced that Junos Space 24.1R2 was released with patches for nearly 60 flaws in third-party components, including critical severity issues in Expat (libexpat), a stream-oriented XML parsing library.
Code updates were also released for numerous medium‑severity vulnerabilities in Junos OS and Junos OS Evolved that could lead to DoS conditions and the disclosure of sensitive information.
None of these vulnerabilities appear to be actively exploited, but users are advised to apply available patches as soon as possible, as it is not uncommon for threat actors to target flaws in Junos OS. Additional information about the vulnerabilities can be found on security advisory page .
See also: Malware botnets exploit outdated D-Link routers
A denial of service (DoS) attack is a malicious attempt to disrupt the normal operation of a targeted server, service, or network by overwhelming it with a flood of traffic. This type of attack aims to make the target inaccessible to users, causing downtime and potential losses. DoS attacks can exploit vulnerabilities or simply use brute force to exhaust resources, and their effects can range from minor malfunctions to major outages.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
