CVE-2025-52989
MEDIUMDescription
An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit permissions, using a specifically crafted annotate configuration command, can change any part of the device configuration. This issue affects: Junos OS: * all versions before 22.2R3-S7, * 22.4 versions before 22.4R3-S7, * 23.2 versions before 23.2R2-S4, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2-S1, * 24.4 versions before 24.4R1-S2, 24.4R2; Junos OS Evolved: * all versions before 22.4R3-S7-EVO, * 23.2-EVO versions before 23.2R2-S4-EVO, * 23.4-EVO versions before 23.4R2-S5-EVO, * 24.2-EVO versions before 24.2R2-S1-EVO * 24.4-EVO versions before 24.4R2-EVO.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
| juniper | junos_os_evolved |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-52989? +
How severe is CVE-2025-52989? +
What products are affected by CVE-2025-52989? +
How do I check if I'm vulnerable to CVE-2025-52989? +
Related Vulnerabilities
Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 …
Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 …
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions …
Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection
Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows …
OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken …