---
id: CVE-2025-59980
title: >-
  An Authentication Bypass by Primary Weakness


  in the FTP server of Juniper Networks Junos OS allows an unauthenticated,
  network-based attacker to get limited read-write access to files on the
  device.

  When the FTP server is enabled and a …
summary: >-
  An Authentication Bypass by Primary Weakness


  in the FTP server of Juniper Networks Junos OS allows an unauthenticated,
  network-based attacker to get limited read-write access to files on the
  device.

  When the FTP server is enabled and a …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-305
vendor: juniper
product: junos
affected:
  - junos < 22.4
  - junos = 22.4
  - junos = 23.2
  - junos = 23.4
patched:
  - junos 22.4
published: '2025-10-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59980'
references:
  - url: 'https://supportportal.juniper.net/JSA103167'
    label: sirt@juniper.net
tags:
  - nvd
epss: 0.00292
epssPercentile: 0.19955
ingestedAt: '2026-10-08T13:42:55.045Z'
---

## Overview

An Authentication Bypass by Primary Weakness

in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device.
When the FTP server is enabled and a user named "ftp" or "anonymous" is configured, that user can login without providing the configured password and then has read-write access to their home directory.

This issue affects Junos OS: 



  *  all versions before 22.4R3-S8,
  *  23.2 versions before 23.2R2-S3,
  *  23.4 versions before 23.4R2.

## Affected

- `junos < 22.4`
- `junos = 22.4`
- `junos = 23.2`
- `junos = 23.4`

## Remediation

Upgrade past the affected range:

- `junos 22.4`
