SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-57025

MEDIUM · CVSS 5.5 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

A vulnerability in the fileio library of Juniper Networks' Junos OS and Junos OS Evolved allows a low-privileged local attacker to execute specific commands that trigger a crash in the l2ald process, resulting in a Denial-of-Service (DoS) condition for all Layer 2 services. This issue affects various EX Series, QFX Series, and MX Series devices running specific versions of the affected operating systems. Network administrators and security teams managing these devices should prioritize applying the relevant updates to mitigate potential service disruptions.

CVE
CVE-2026-57025
Severity
MEDIUM
CVSS
5.5
EPSS
0.10%

Original NVD Description

A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted. This issue affects EX Series, QFX Series, MX Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24.4R1-S3-EVO.

Related CVEs

Other vulnerabilities affecting the same vendor(s)