Improper Privilege Management in ZTE GoldenDB
CVE-2025-26704

4.3MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
11 March 2025

What is CVE-2025-26704?

The ZTE GoldenDB product is affected by a weakness related to improper privilege management, permitting unauthorized escalation of privileges within the affected versions. This vulnerability, which spans from version 6.1.03 through 6.1.03.05, poses a significant risk as it allows malicious actors to gain elevated access and control, potentially leading to unauthorized modifications or data breaches. Users are strongly advised to review the security bulletin provided by ZTE and implement recommended patches to mitigate this risk.

Affected Version(s)

GoldenDB 6.1.03 <= 6.1.03.05

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-26704 : Improper Privilege Management in ZTE GoldenDB