Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-59978


An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.


Published

2025-10-09T17:15:59.250

Last Modified

2026-01-23T19:44:53.170

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application juniper junos_space < 24.1 Yes
Application juniper junos_space 24.1 Yes
Application juniper junos_space 24.1 Yes
Application juniper junos_space 24.1 Yes

References