CVE-2025-60001: Junos Space: Create Quick Template page is vulnerable to reflected cross-site script injection
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue affects all versions of Junos Space before 24.1R4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60001?
CVE-2025-60001 is considered a high-severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-60001?
To fix CVE-2025-60001, upgrade to a version of Juniper Networks Junos Space that is patched beyond version 24.1R4.
What type of vulnerability is CVE-2025-60001?
CVE-2025-60001 is classified as a Cross-site Scripting (XSS) vulnerability affecting web page generation.
What can an attacker do with CVE-2025-60001?
An attacker can inject malicious script tags into the Generate Report page to execute arbitrary commands on behalf of another user.
Which software is affected by CVE-2025-60001?
CVE-2025-60001 affects Juniper Networks Junos Space, specifically versions up to 24.1R4.