CVE-2025-46579
ZTE GoldenDB Database product has a DDE injection vulnerability
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.4EPSS 0.3%KEV nãoPoC —Patch —
Lifecycle
27 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected products
ZTE · GoldenDBWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →