CVE-2025-52958: Juniper Junos

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).On all Junos OS and Junos OS Evolved devices, when route validation is enabled, a rare condition during BGP initial session establishment can lead to an rpd crash and restart. This occurs specifically when the connection request fails during error-handling scenario. Continued session establishment failures leads to a sustained DoS condition.  This issue affects Junos OS: * All versions before 22.2R3-S6, * from 22.4 before 22.4R3-S6, * from 23.2 before 23.2R2-S3, * from 23.4 before 23.4R2-S4, * from 24.2 before 24.2R2; Junos OS Evolved: * All versions before 22.2R3-S6-EVO, * from 22.4 before 22.4R3-S6-EVO, * from 23.2 before 23.2R2-S3-EVO, * from 23.4 before 23.4R2-S4-EVO, * from 24.2 before 24.2R2-EVO.

Affected products

  • Juniper Junos: before 22.2 (fixed in 22.2); version 22.2 only; version 22.4 only; version 23.2 only; version 23.4 only; version 24.2 only
  • Juniper Junos OS Evolved: before 22.2 (fixed in 22.2); version 22.2 only; version 22.4 only; version 23.2 only; version 23.4 only; version 24.2 only

Published 2025-07-11. Last modified 2026-06-17.