CVE-2017-10937: ZTE Zxiptv-Ucm Firmware

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.

Affected products

  • ZTE Zxiptv-Ucm Firmware: before 2.01.05.09 (fixed in 2.01.05.09)

Published 2018-07-25. Last modified 2026-06-17.