← back
CVE-2025-46579

ZTE GoldenDB Database product has a DDE injection vulnerability

CVSS 8.4 HIGHEPSS 0.3%CWE-94
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.4EPSS 0.3%KEV nãoPoC Patch
Lifecycle
27 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected products
ZTE · GoldenDB

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →