Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-59992


An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Secure Console page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue affects all versions of Junos Space before 24.1R4.


Published

2025-10-09T17:16:01.507

Last Modified

2026-01-23T20:00:18.100

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application juniper junos_space < 24.1 Yes
Application juniper junos_space 24.1 Yes
Application juniper junos_space 24.1 Yes
Application juniper junos_space 24.1 Yes

References