CVE-2025-59989: Junos Space: Device Discovery page is vulnerable to reflected cross-site script injection
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Device Discovery page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue affects all versions of Junos Space before 24.1R4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59989?
CVE-2025-59989 is considered a high-severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-59989?
To fix CVE-2025-59989, upgrade Juniper Networks Junos Space to version 24.1R5 or later.
What impact does CVE-2025-59989 have on users?
CVE-2025-59989 allows attackers to execute malicious scripts in the context of other users visiting the affected Device Discovery page.
Is there a workaround for CVE-2025-59989 before applying the patch?
As of now, there is no officially documented workaround for CVE-2025-59989; applying the patch is recommended.
What software versions are affected by CVE-2025-59989?
CVE-2025-59989 affects Juniper Networks Junos Space versions up to and including 24.1R4.