CVE-2025-59975: Junos Space: Flooding device with inbound API calls leads to WebUI and CLI management access DoS

Published Oct 9, 2025
·
Updated

An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound API calls to consume all resources on the system, leading to a Denial of Service (DoS).

After continuously flooding the system with inbound connection requests, all available file handles become consumed, blocking access to the system via SSH and the web user interface (WebUI), resulting in a management interface DoS. A manual reboot of the system is required to restore functionality.

This issue affects Junos Space: all versions before 22.2R1 Patch V3, from 23.1 before 23.1R1 Patch V3.

Affected Software

4 affected components
Juniper Networks Junos Space<22.2R1 Patch V3, >=undefined
Juniper Junos Space<22.2
Juniper Junos Space=22.2-r1
Juniper Junos Space=23.1-r1

Remediation

Information

The following software releases have been updated to resolve this specific issue: Junos Space 22.2R1 Patch V3, 23.1R1 Patch V3, 24.1R1, and all subsequent releases.

Event History

Oct 9, 2025
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-59975?

CVE-2025-59975 is a high severity vulnerability that can lead to Denial of Service (DoS) due to resource exhaustion.

2

How do I fix CVE-2025-59975?

To fix CVE-2025-59975, update the Junos Space software to a patched version, ensuring it is above 22.2R1 Patch V3.

3

What type of attack does CVE-2025-59975 expose Junos Space to?

CVE-2025-59975 exposes Junos Space to Denial of Service (DoS) attacks by flooding the system with excessive API calls.

4

Can CVE-2025-59975 be exploited remotely?

Yes, CVE-2025-59975 can be exploited by unauthenticated network-based attackers.

5

What does CVE-2025-59975 affect in Junos Space?

CVE-2025-59975 affects the HTTP daemon (httpd) of Junos Space, leading to resource consumption issues.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203