CVE-2017-10936: ZTE Zxcdn-Sns Firmware
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.
Affected products
- ZTE Zxcdn-Sns Firmware: before 4.01.01 (fixed in 4.01.01)
Published 2018-07-25. Last modified 2026-06-17.