OS Command Injection Vulnerability in Juniper Networks Junos OS Evolved
CVE-2025-60006

4.8MEDIUM

Key Information:

Vendor
CVE Published:
9 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-60006?

An OS command injection vulnerability exists in the CLI of Juniper Networks Junos OS Evolved. This flaw arises due to improper handling of special elements, allowing attackers to execute crafted commands that could lead to privilege escalation or unauthorized command execution. When specific commands are processed through unprotected scripts, they may inadvertently be executed via the operating system shell, potentially enabling attackers to perform actions beyond their intended permissions. The issue impacts specific versions of Junos OS Evolved and necessitates prompt remediation to mitigate risks.

Affected Version(s)

Junos OS Evolved 24.2 < 24.2R2-S2-EVO

Junos OS Evolved 24.4 < 24.4R2-EVO

Junos OS Evolved 0 < 24.2R1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-60006 : OS Command Injection Vulnerability in Juniper Networks Junos OS Evolved