ZTE GoldenDB Database DDE Injection Vulnerability

Vulnerability

A DDE injection vulnerability exists in ZTE's GoldenDB database product. This issue allows attackers to inject DDE expressions via the interface. When users download and open the affected file, the injected DDE commands can be executed.

Impact

Exploitation of this vulnerability allows for DDE injection, where executed commands can be controlled by the attacker.

Remediation

Users can upgrade to version 6.1.03.11, 7.2.01.01P1, or Lite7.2.01.01P1. For assistance, contact the ZTE Global Customer Support Center.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.5
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.