Cross-Site Scripting Vulnerability in Juniper Networks Junos Space
CVE-2025-59978
9.4CRITICAL
Key Information:
- Vendor
Juniper Networks
- Status
- Vendor
- CVE Published:
- 9 October 2025
Badges
👾 Exploit Exists
What is CVE-2025-59978?
A cross-site scripting vulnerability in Juniper Networks' Junos Space enables attackers to embed malicious script tags within web pages. When these pages are accessed by other users, the scripts can execute commands under the administrative privileges of the targets. This flaw poses a significant risk as it potentially allows an attacker to gain unauthorized control, manipulate settings, or extract sensitive information from users who interact with the compromised pages. The issue impacts all versions of Junos Space released before 24.1R4, necessitating prompt attention to mitigate associated risks.
Affected Version(s)
Junos Space 0 < 24.1R4
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Juniper SIRT would like to acknowledge and thank Arnoldas Radisauskas and Jorge Escabias from NATO Cyber Security Center for responsibly reporting this vulnerability.