CVE-2025-46579: ZTE Zxcloud Goldendb
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.
Affected products
- ZTE Zxcloud Goldendb: from 6.1.03, before 6.1.03.11 (fixed in 6.1.03.11); version 7.2.01.01 only
Published 2025-04-27. Last modified 2026-06-17.