Privilege Escalation Vulnerability in ZTE GoldenDB
CVE-2025-26707

5.3MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
11 March 2025

What is CVE-2025-26707?

The ZTE GoldenDB product suffers from an improper privilege management vulnerability, which allows an attacker to escalate privileges. This vulnerability affects multiple versions from 6.1.03 through to 6.1.03.05, enabling a malicious actor to gain unauthorized access or control over certain operations within the database. Users of the impacted versions are encouraged to assess their systems and apply necessary patches or mitigations as per the vendor's guidance to safeguard against potential exploitation.

Affected Version(s)

GoldenDB 6.1.03 <= 6.1.03.05

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.