Network administrators using Juniper Networks ’ PTX series routers in their environments are urged to apply updates immediately , as a newly discovered critical vulnerability could allow an unauthenticated attacker to execute code with root privileges . The vulnerability is “ particularly dangerous because these devices are often at the heart of the network ,” said Piyush Sharma , CEO of Tuskira .

«If an attacker gains control of a PTX, the impact goes beyond simply compromising a device, as it can become monitoring point traffic and a control point at the same time. This opens the door to covertly intercepting data streams, redirecting traffic , or easily accessing neighboring networks.».
The issue affects PTX routers running Junos OS Evolved versions prior to 25.4R1-S1-EVO and 25.4R2-EVO. It does not affect standard Junos OS.
See also: Trend Micro: Critical vulnerabilities in Apex One
Juniper Networks PTX core routers
In a statement, Juniper said it is not aware of any exploits for this vulnerability. The vulnerability was discovered during internal product security testing or research. The PTX series is a line of high-performance modular core routers powered by HPE Juniper Networks’ latest generation of custom Express family ASICs and optimized for 400G and 800G migrations.
They offer native 400G and 800G inline MACsec, deep buffering , and flexible filtering. The company says they are built for longevity in demanding WAN and data center use cases and deployment scenarios including core, peering, data center interconnect, data center edge, metro aggregation, and AI data center networking.
In its announcement, Juniper says that an “Incorrect Permission Assignment for Critical Resource” vulnerability in On-Box Anomaly detection framework allows an unauthenticated attacker to execute code as root. The detection framework is enabled by default.
See also: Claude Code: Vulnerabilities allow RCE attacks and API key theft

“The On-Box anomaly detection framework should only be accessible to other internal processes via internal routing, but not via an externally exposed port,” the notice adds. “By being able to access and manipulate the service to execute code as root, a remote attacker could take complete control of the device.”
Vulnerability management
To resolve the issue, administrators should ensure that Junos OS Evolved version 25.4R1-S1-EVO is installed.
They should also note that versions 25.4R2-EVO and 26.2R1-EVO are on the way. If the update cannot be installed immediately, administrators should use lists access control or firewall filters to restrict access to only trusted networks and hosts.
Another option is to disable the service by entering request pfe anomalies disable in the operating system command line.
Sharma said Juniper vulnerabilities have attracted hackers' attention in recent years because of the advantageous position routers provide. "As a network operating system, Junos sits at the crossroads of important control points such as identity, policies and traffic, which means a single exploit can quickly scale across valuable networks," he said.
See also: Zyxel: Critical RCE vulnerability affects many routers
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“Furthermore, these locations provide attackers with a larger window to find and exploit vulnerable devices, as core network equipment is difficult to update due to long downtimes.” To prevent vulnerabilities like the current loophole from being exploited, organizations need a defense platform that can continuously monitor for anomalies in networks and alert security teams when malicious behavior.
The vulnerability disclosure comes as Juniper's parent company, HPE, prepares to introduce new PTX12000 and PTX10002 router at Mobile World Congress. HPE bought Juniper last year.
