Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands. When an attacker executes crafted CLI commands, the options are processed via a script in some cases. These scripts are not hardened so injected commands might be executed via the shell, which allows an attacker to perform operations, which they should not be able to do according to their assigned permissions. This issue affects Junos OS Evolved: * 24.2 versions before 24.2R2-S2-EVO, * 24.4 versions before 24.4R2-EVO. This issue does not affect Junos OS Evolved versions earlier than 24.2R1-EVO.
Conclusion & alert: CVE-2025-60006 is rated Low Risk (30.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.12%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-08 | 0.17% | 0.12% | -0.04% |
| 2 | 2026-03-07 | 0.31% | 0.17% | -0.14% |
| 3 | 2026-01-24 | — | 0.31% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.8 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
1.8 | 3.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| juniper | junos_os_evolved | 24.2 | cpe:2.3:o:juniper:junos_os_evolved:24.2:-:*:*:*:*:*:* |
| juniper | junos_os_evolved | 24.2 | cpe:2.3:o:juniper:junos_os_evolved:24.2:r1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 24.2 | cpe:2.3:o:juniper:junos_os_evolved:24.2:r1-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 24.2 | cpe:2.3:o:juniper:junos_os_evolved:24.2:r2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 24.2 | cpe:2.3:o:juniper:junos_os_evolved:24.2:r2-s1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 24.4 | cpe:2.3:o:juniper:junos_os_evolved:24.4:-:*:*:*:*:*:* |
| juniper | junos_os_evolved | 24.4 | cpe:2.3:o:juniper:junos_os_evolved:24.4:r1:*:*:*:*:*:* |
| juniper | junos_os_evolved | 24.4 | cpe:2.3:o:juniper:junos_os_evolved:24.4:r1-s2:*:*:*:*:*:* |
| juniper | junos_os_evolved | 24.4 | cpe:2.3:o:juniper:junos_os_evolved:24.4:r1-s3:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://supportportal.juniper.net/JSA103163 | Vendor Advisory |