CVE-2025-46578: ZTE Zxcloud Goldendb

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.

Affected products

  • ZTE Zxcloud Goldendb: from 6.1.03, before 6.1.03.11 (fixed in 6.1.03.11); version 7.2.01.01 only

Published 2025-04-27. Last modified 2026-06-17.