Get real-time updates on Telegram
CVE-2025-59982: junos space before 24.1 (exclusive), 24.1 · update r1, 24.1 · update r2 (+1 more affected versions); +1 more affected…
CVE-2025-59982. CVSS 3.1 base score 6.1 (MEDIUM, Vendor/CNA). EPSS 0.00275 (percentile 0.1816), scored 2026-10-06.
Affected technology
junos space · before 24.1 (exclusive)
juniper
junos space · 24.1 · update r1
juniper
junos space · 24.1 · update r2
juniper
junos space · 24.1 · update r3
juniper
Junos Space · 0 to before 24.1R4
Juniper Networks
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · Active user interaction
What an attacker can do
An attacker can inject script tags in the dashboard search field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue affects all versions of Junos Space before 24.1R4. Vendor/CNA’s CVSS 4.0 assessment (base score 5.1/10) rates confidentiality, integrity and availability impact as none.
- CWE
- CWE-79
- CCR priority
- 24.5 /100 (P4)
- CVSS 3.1
- 6.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N · Vendor/CNA
- EPSS
- 0.00275 · percentile 0.18239 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-59982.html