OS Command Injection Vulnerability in Juniper Networks Junos OS Evolved
CVE-2025-60006
4.8MEDIUM
Key Information:
- Vendor
Juniper Networks
- Status
- Vendor
- CVE Published:
- 9 October 2025
Badges
👾 Exploit Exists
What is CVE-2025-60006?
An OS command injection vulnerability exists in the CLI of Juniper Networks Junos OS Evolved. This flaw arises due to improper handling of special elements, allowing attackers to execute crafted commands that could lead to privilege escalation or unauthorized command execution. When specific commands are processed through unprotected scripts, they may inadvertently be executed via the operating system shell, potentially enabling attackers to perform actions beyond their intended permissions. The issue impacts specific versions of Junos OS Evolved and necessitates prompt remediation to mitigate risks.
Affected Version(s)
Junos OS Evolved 24.2 < 24.2R2-S2-EVO
Junos OS Evolved 24.4 < 24.4R2-EVO
Junos OS Evolved 0 < 24.2R1