CVE-2025-59996: Junos Space: Configuration View page is vulnerable to reflected cross-site script injection
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Configuration View page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue affects all versions of Junos Space before 24.1R4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59996?
The severity of CVE-2025-59996 is considered critical due to its potential to allow attackers to execute unauthorized scripts.
How do I fix CVE-2025-59996?
To fix CVE-2025-59996, update your Juniper Networks Junos Space software to the latest version, ideally beyond 24.1R4, where the vulnerability has been addressed.
What types of attacks are possible with CVE-2025-59996?
CVE-2025-59996 can be exploited for cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into the browser of users visiting the affected configuration page.
Which products are affected by CVE-2025-59996?
CVE-2025-59996 affects Juniper Networks Junos Space, specifically versions up to but not including 24.1R4.
How can I determine if my system is vulnerable to CVE-2025-59996?
You can determine if your system is vulnerable to CVE-2025-59996 by checking the version of Junos Space you are running and comparing it against the listed affected versions.