CVE-2017-10937: ZTE Zxiptv-Ucm Firmware
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.
Affected products
- ZTE Zxiptv-Ucm Firmware: before 2.01.05.09 (fixed in 2.01.05.09)
Published 2018-07-25. Last modified 2026-06-17.