CVE-2025-46579

There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zte:zxcloud_goldendb:*:*:*:*:*:*:*:*
cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:-:*:*:*
cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:lite:*:*:*

History

12 May 2025, 19:32

Type Values Removed Values Added
CPE cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:-:*:*:*
cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:lite:*:*:*
cpe:2.3:a:zte:zxcloud_goldendb:*:*:*:*:*:*:*:*
References () https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/1036467615091601474 - () https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/1036467615091601474 - Vendor Advisory
First Time Zte zxcloud Goldendb
Zte
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

27 Apr 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-27 02:15

Updated : 2025-05-12 19:32


NVD link : CVE-2025-46579

Mitre link : CVE-2025-46579


JSON object : View

Products Affected

zte

  • zxcloud_goldendb
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')