CVE-2025-46579: ZTE GoldenDB Database product has a DDE injection vulnerability
There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46579?
CVE-2025-46579 is considered a high-severity vulnerability due to its potential for remote code execution.
How does CVE-2025-46579 work?
CVE-2025-46579 allows attackers to inject DDE expressions through the GoldenDB database interface, executing commands when the file is opened by users.
What software is affected by CVE-2025-46579?
The vulnerability impacts the ZTE GoldenDB database product.
How do I fix CVE-2025-46579?
To mitigate CVE-2025-46579, users should apply the latest security patches provided by ZTE for GoldenDB.
Can CVE-2025-46579 be exploited remotely?
Yes, CVE-2025-46579 can be exploited remotely, allowing attackers to execute arbitrary commands on affected systems.