CVE-2025-46578: ZTE Zxcloud Goldendb
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.
Affected products
- ZTE Zxcloud Goldendb: from 6.1.03, before 6.1.03.11 (fixed in 6.1.03.11); version 7.2.01.01 only
Published 2025-04-27. Last modified 2026-06-17.