---
id: CVE-2025-30650
title: "A\_Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.\n\nThis issue affects systems running Juno…"
summary: "A\_Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.\n\nThis issue affects systems running Juno…"
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
published: '2026-04-08'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-30650'
references:
  - url: >-
      https://github.com/orangecertcc/security-research/security/advisories/GHSA-fwhc-gh5m-v8fq
    label: sirt@juniper.net
  - url: 'https://kb.juniper.net/JSA107863'
    label: sirt@juniper.net
tags:
  - nvd
epss: 0.00137
epssPercentile: 0.0249
ingestedAt: '2026-07-26T00:06:15.225Z'
---

## Overview

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.

This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include:
  *  MPC7, MPC8, MPC9, MPC10, MPC11
  *  LC2101, LC2103
  *  LC480, LC4800, LC9600
  *  MX304 (built-in FPC)
  *  MX-SPC3
  *  SRX5K-SPC3
  *  EX9200-40XS


  *  FPC3-PTX-U2, FPC3-PTX-U3
  *  FPC3-SFF-PTX
  *  LC1101, LC1102, LC1104, LC1105





This issue affects Junos OS: 



  *  all versions before 22.4R3-S8, 
  *  from 23.2 before 23.2R2-S6, 
  *  from 23.4 before 23.4R2-S6, 
  *  from 24.2 before 24.2R2-S3, 
  *  from 24.4 before 24.4R2,
  *  from 25.2 before 25.2R2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
