← Vulnerability feed

Vulnerability record · CVE-2025-59978 · published 9 October 2025

CVE-2025-59978: Juniper junos space cross-site scripting vulnerability

Juniper · Junos Space

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.

9.4 CVSS 4.0 Critical EPSS 0.53% · top 57.4% CWE-79 · Cross-site scripting
9.4CVSS 4.0 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59978 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-3412Juniper junos space vulnerabilityUnspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, allows remote attackers to execute arbitrary command…EPSS 4.7%10.0CVE-2014-2421Canonical ubuntu linux vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect con…EPSS 6.6%10.0CVE-2014-0456Canonical ubuntu linux vulnerabilityUnspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrit…EPSS 6.6%10.0CVE-2014-0457Oracle jrockit vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attack…EPSS 6.6%10.0CVE-2014-0429Canonical ubuntu linux vulnerabilityUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers…EPSS 7.3%9.8CVE-2014-3413Juniper junos space hard-coded credentials vulnerabilityThe MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers …EPSS 2.1%9.8CVE-2017-10622Juniper junos space improper authentication vulnerabilityAn authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based a…EPSS 5.4%9.8CVE-2016-1265Juniper junos space information exposure vulnerabilityA remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices manage…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2025-59978), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.