Cross-Site Scripting Vulnerability in Juniper Networks Junos Space
CVE-2025-59978

9.4CRITICAL

Key Information:

Vendor
CVE Published:
9 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-59978?

A cross-site scripting vulnerability in Juniper Networks' Junos Space enables attackers to embed malicious script tags within web pages. When these pages are accessed by other users, the scripts can execute commands under the administrative privileges of the targets. This flaw poses a significant risk as it potentially allows an attacker to gain unauthorized control, manipulate settings, or extract sensitive information from users who interact with the compromised pages. The issue impacts all versions of Junos Space released before 24.1R4, necessitating prompt attention to mitigate associated risks.

Affected Version(s)

Junos Space 0 < 24.1R4

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Juniper SIRT would like to acknowledge and thank Arnoldas Radisauskas and Jorge Escabias from NATO Cyber Security Center for responsibly reporting this vulnerability.
.
CVE-2025-59978 : Cross-Site Scripting Vulnerability in Juniper Networks Junos Space