Juniper Networks Junos OS FTP Server Authentication Bypass Vulnerability Allowing Unauthorized Read-Write File Access

Vulnerability

A vulnerability in the FTP server of Juniper Networks Junos OS has been identified, allowing an unauthenticated, network-based attacker to bypass authentication and gain limited read-write access to files on the device. This issue arises when the FTP server is enabled and a user named 'ftp' or 'anonymous' is configured. In such cases, the user can log in without providing the correct password and access their home directory. This vulnerability affects all Junos OS versions prior to 22.4R3-S8, as well as 23.2 versions prior to 23.2R2-S3 and 23.4 versions prior to 23.4R2.

Impact

Exploitation of this vulnerability allows for authentication bypass, granting unauthorized users read-write access to files in the home directory of the 'ftp' or 'anonymous' user on the affected device.

Added: Oct 9, 2025, 5:35 PM
Updated: Oct 9, 2025, 5:35 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
1.3
exploitability
7.0
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.