Network Security

Juniper Addresses Router Flaw Actively-Exploited By Chinese Threat Group

Flag of China

BleepingComputer reports that Juniper Networks issued patches to resolve a medium-severity Junos OS flaw impacting several of its routers, tracked as CVE-2025-21590. The bug was disclosed by Google's Mandiant team to have been exploited by Chinese cyberespionage hacking group UNC3886 to facilitate the deployment of six different TINYSHELL-based backdoors in a 2024 attack.

"Customers are encouraged to upgrade to a fixed release as soon as it's available and in the meantime take steps to mitigate this vulnerability," said Juniper. "While the complete list of resolved platforms is under investigation, it is strongly recommended to mitigate the risk of exploitation by restricting shell access to trusted users only."

Juniper also noted that the security issue stemmed from inadequate isolation or compartmentalization. The flaw has also been added to the Cybersecurity and Infrastructure Security Agency's (CISAs) Known Exploited Vulnerabilities (KEV) catalog. Federal agencies were urged to remediate the bug by April 3.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

You can skip this ad in 5 seconds

Cookies

This website uses cookies to improve your experience, provide social media features and deliver advertising offers that are relevant to you.

If you continue without changing your settings, you consent to our use of cookies in accordance with our privacy policy. You may disable cookies.