SQL Injection Vulnerability in ZTE ICCP Web Interface
CVE-2026-9668

6.3MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-9668?

This vulnerability in the ZTE ICCP Web Interface allows attackers with legitimate user credentials to exploit the system by crafting malicious SQL statements. This exploitation facilitates the bypassing of authentication mechanisms, enabling unauthorized execution of arbitrary database queries. As a result, this can lead to performance issues such as slow database responses and an increased risk of exposing sensitive information. The vulnerability's low exploitation threshold and extensive impact underscore the necessity for an immediate patch to protect affected systems.

Affected Version(s)

SCP ZENIC-ONE-R20-SCP-V16.25.20.071

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PPC Security Team and Dimitrios Tsilis
.