in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device.
When the FTP server is enabled and a user named "ftp" or "anonymous" is configured, that user can login without providing the configured password and then has read-write access to their home directory.
This issue affects Junos OS:
* all versions before 22.4R3-S8,
* 23.2 versions before 23.2R2-S3,
* 23.4 versions before 23.4R2.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
The following software releases have been updated to resolve this specific issue: 22.4R3-S8, 23.2R2-S3, 23.4R2, 24.2R1, and all subsequent releases.
Workaround
Choosing another name for the user "ftp" or "anonymous" will prevent exploitation of this issue.
Link | Providers |
---|---|
https://supportportal.juniper.net/JSA103167 |
![]() ![]() |
Thu, 09 Oct 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 09 Oct 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access to files on the device. When the FTP server is enabled and a user named "ftp" or "anonymous" is configured, that user can login without providing the configured password and then has read-write access to their home directory. This issue affects Junos OS: * all versions before 22.4R3-S8, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2. | |
Title | Junos OS: When a user with the name ftp or anonymous is configured unauthenticated filesystem access is allowed | |
Weaknesses | CWE-305 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: juniper
Published:
Updated: 2025-10-09T19:49:01.776Z
Reserved: 2025-09-23T18:19:06.957Z
Link: CVE-2025-59980

Updated: 2025-10-09T19:45:38.020Z

Status : Received
Published: 2025-10-09T17:15:59.427
Modified: 2025-10-09T17:15:59.427
Link: CVE-2025-59980

No data.

No data.