CVE 6.5 MEDIUM

Junos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem access is allowed_CVE-2025-59980

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

An Authentication Bypass by Primary Weakness

in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device.
When the FTP server is enabled and a user named "ftp" or "anonymous" is configured, that user can login without providing the configured password and then has read-write access to their home directory.

This issue affects Junos OS: 



* all versions before 22.4R3-S8,
* 23.2 versions before 23.2R2-S3,
* 23.4 versions before 23.4R2.

Basic Information

ID CVE-2025-59980
Source juniper
Published Oct 9, 2025 at 16:05
Modified Oct 9, 2025 at 19:49

Affected Product

Vendor Juniper Networks
Product Junos OS
Affected Versions Juniper Networks Junos OS 0
Juniper Networks Junos OS 23.2
Juniper Networks Junos OS 23.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.