@karand's solution and information is correct, but if ALL you want to be able to do is reach the radius server, configured in default VR (inet.0), and keep all other traffic separated between the VRs (I assume you have some sort of external device/FW that allows some traffic between VRs) then all you need to do is add a static route(s) to the radius server(s) in each VR which could actually be a /32 host route.
Hopefully this makes sense to you, and is probably much easier than route leaking, if indeed this is the only route (besides their own) that each VR needs.