SQL Injection Vulnerability in ZTE ICCP Web Interface
CVE-2026-9668
6.3MEDIUM
What is CVE-2026-9668?
This vulnerability in the ZTE ICCP Web Interface allows attackers with legitimate user credentials to exploit the system by crafting malicious SQL statements. This exploitation facilitates the bypassing of authentication mechanisms, enabling unauthorized execution of arbitrary database queries. As a result, this can lead to performance issues such as slow database responses and an increased risk of exposing sensitive information. The vulnerability's low exploitation threshold and extensive impact underscore the necessity for an immediate patch to protect affected systems.
Affected Version(s)
SCP ZENIC-ONE-R20-SCP-V16.25.20.071
