CVE-2025-59958

MEDIUM
Published Oct 9, 2025 Modified Jan 23, 2026 CWE-754

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to cause impact to confidentiality and availability. When an output firewall filter is configured with one or more terms where the action is 'reject', packets matching these terms are erroneously sent to the Routing Engine (RE) and further processed there. Processing of these packets will consume limited RE resources. Also responses from the RE back to the source of this traffic could reveal confidential information about the affected device. This issue only applies to firewall filters applied to WAN or revenue interfaces, so not the mgmt or lo0 interface of the routing-engine, nor any input filters. This issue affects Junos OS Evolved on PTX Series: * all versions before 22.4R3-EVO, * 23.2 versions before 23.2R2-EVO.

Is your site exposed to CVE-2025-59958?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Weakness Type (CWE)

CWE-754 CWE-754

Affected Products

Vendor Product
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper junos_os_evolved
juniper ptx1000
juniper ptx10001-36mr
juniper ptx10002
juniper ptx10003
juniper ptx10004
juniper ptx10008
juniper ptx10016
juniper ptx3000
juniper ptx5000

References

Frequently Asked Questions

What is CVE-2025-59958? +
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to cause impact to confidentiality and availability. When an output firewall filter is configured with one or more terms where the action is 'reject', packets matching these terms are erroneously sent to the Routing Engine (RE) and further processed there. Processing of these packets will consume limited RE resources. Also responses from the RE back to the source of this traffic could reveal confidential information about the affected device. This issue only applies to firewall filters applied to WAN or revenue interfaces, so not the mgmt or lo0 interface of the routing-engine, nor any input filters. This issue affects Junos OS Evolved on PTX Series: * all versions before 22.4R3-EVO, * 23.2 versions before 23.2R2-EVO. It has a CVSS v3.1 base score of 6.5 (MEDIUM).
How severe is CVE-2025-59958? +
CVE-2025-59958 has a CVSS v3.1 score of 6.5 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2025-59958? +
CVE-2025-59958 affects products from juniper, specifically: junos_os_evolved, ptx1000, ptx10001-36mr, ptx10002, ptx10003, ptx10004, ptx10008, ptx10016, ptx3000, ptx5000. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-59958? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-59958 — free, no signup required.